CVE-2026-92747: Invocation of Process Using Visible Sensitive Information in Red Hat Red Hat Enterprise Linux 10
A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This occurs when the `install_machine.py` script passes these credentials as a JSON command-line argument during VM creation or installation. The exposure is limited to the period when the installation workflow is active and depends on host process-visibility policies.
AI Analysis
Technical Summary
This vulnerability arises from the install_machine.py script in cockpit-machines passing sensitive guest VM credentials (rootPassword and userPassword) as JSON command-line arguments during VM creation or installation. Local attackers with the ability to inspect running processes on the host can expose these credentials. The exposure window is limited to the active installation workflow and is contingent on host process-visibility settings. Red Hat is currently investigating this issue, and no explicit patch or fix status is provided in the advisory.
Potential Impact
The impact is the potential exposure of sensitive guest VM credentials to local users who can inspect running processes on the host. This could lead to unauthorized access to guest VMs if an attacker obtains these credentials. The exposure is temporary and limited to the installation period and depends on host process-visibility policies. There is no indication of remote exploitation or impact beyond credential disclosure.
Mitigation Recommendations
Red Hat's advisory states the issue is under investigation and does not currently provide a patch or official fix. Since the exposure depends on host process-visibility policies, restricting local user access and limiting process inspection capabilities can reduce risk. Monitor Red Hat's advisory page for updates and apply any forthcoming patches or mitigations as recommended.
CVE-2026-92747: Invocation of Process Using Visible Sensitive Information in Red Hat Red Hat Enterprise Linux 10
Description
A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This occurs when the `install_machine.py` script passes these credentials as a JSON command-line argument during VM creation or installation. The exposure is limited to the period when the installation workflow is active and depends on host process-visibility policies.
CVSS v3.1
Score 5.0medium
Affected software
Red Hat
Red Hat Enterprise Linux 10
Red Hat
Red Hat Enterprise Linux 9
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises from the install_machine.py script in cockpit-machines passing sensitive guest VM credentials (rootPassword and userPassword) as JSON command-line arguments during VM creation or installation. Local attackers with the ability to inspect running processes on the host can expose these credentials. The exposure window is limited to the active installation workflow and is contingent on host process-visibility settings. Red Hat is currently investigating this issue, and no explicit patch or fix status is provided in the advisory.
Potential Impact
The impact is the potential exposure of sensitive guest VM credentials to local users who can inspect running processes on the host. This could lead to unauthorized access to guest VMs if an attacker obtains these credentials. The exposure is temporary and limited to the installation period and depends on host process-visibility policies. There is no indication of remote exploitation or impact beyond credential disclosure.
Mitigation Recommendations
Red Hat's advisory states the issue is under investigation and does not currently provide a patch or official fix. Since the exposure depends on host process-visibility policies, restricting local user access and limiting process inspection capabilities can reduce risk. Monitor Red Hat's advisory page for updates and apply any forthcoming patches or mitigations as recommended.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-09-16T18:50:18.131Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-92747","vendor":"Red Hat"}]
Threat ID: 6aad7cac55bf5e2cf55a40b1
Added to database: 09/18/2026, 18:02:20 UTC
Last enriched: 09/18/2026, 18:17:24 UTC
Last updated: 09/19/2026, 01:17:24 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.