CVE-2026-93685: Exposure of Sensitive Information to an Unauthorized Actor in Red Hat Red Hat Advanced Cluster Management for Kubernetes 2
A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details, after completing a basic encrypted connection. This vulnerability does not enable direct remote code execution.
AI Analysis
Technical Summary
A flaw in the multicluster-observability-addon of Red Hat Advanced Cluster Management for Kubernetes 2 allows remote attackers to access debug endpoints without authentication because of a misconfiguration in the underlying addon-framework library. This unauthorized access exposes sensitive operational information including goroutine, heap, and command-line details after completing a trivial TLS handshake. Although this vulnerability does not enable direct remote code execution, it increases the attack surface by providing attackers with reconnaissance data. The vulnerability affects the debug endpoints exposed on port 8443 and port 6060. Red Hat recommends restricting network access to the pods running the multicluster-observability-addon to trusted internal components and applying network policies to block untrusted inbound connections to these ports.
Potential Impact
The vulnerability allows unauthorized disclosure of sensitive operational information such as goroutine stacks, heap data, and command-line arguments. This information leakage can aid attackers in reconnaissance activities but does not allow direct remote code execution or integrity compromise. The impact is limited to confidentiality and availability with low severity on confidentiality and availability, and no impact on integrity.
Mitigation Recommendations
Red Hat advises restricting network access to the pods running the multicluster-observability-addon to trusted internal components only. Implement Kubernetes network policies to limit inbound connections on ports 6060 and 8443 to trusted sources, thereby preventing unauthorized access to the unauthenticated debug endpoints. No official patch or fix is currently indicated in the advisory; operational controls are the recommended mitigation.
CVE-2026-93685: Exposure of Sensitive Information to an Unauthorized Actor in Red Hat Red Hat Advanced Cluster Management for Kubernetes 2
Description
A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details, after completing a basic encrypted connection. This vulnerability does not enable direct remote code execution.
CVSS v3.1
Score 5.4medium
Affected software
Red Hat
Red Hat Advanced Cluster Management for Kubernetes 2
Red Hat
Red Hat Advanced Cluster Management for Kubernetes 2
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A flaw in the multicluster-observability-addon of Red Hat Advanced Cluster Management for Kubernetes 2 allows remote attackers to access debug endpoints without authentication because of a misconfiguration in the underlying addon-framework library. This unauthorized access exposes sensitive operational information including goroutine, heap, and command-line details after completing a trivial TLS handshake. Although this vulnerability does not enable direct remote code execution, it increases the attack surface by providing attackers with reconnaissance data. The vulnerability affects the debug endpoints exposed on port 8443 and port 6060. Red Hat recommends restricting network access to the pods running the multicluster-observability-addon to trusted internal components and applying network policies to block untrusted inbound connections to these ports.
Potential Impact
The vulnerability allows unauthorized disclosure of sensitive operational information such as goroutine stacks, heap data, and command-line arguments. This information leakage can aid attackers in reconnaissance activities but does not allow direct remote code execution or integrity compromise. The impact is limited to confidentiality and availability with low severity on confidentiality and availability, and no impact on integrity.
Mitigation Recommendations
Red Hat advises restricting network access to the pods running the multicluster-observability-addon to trusted internal components only. Implement Kubernetes network policies to limit inbound connections on ports 6060 and 8443 to trusted sources, thereby preventing unauthorized access to the unauthenticated debug endpoints. No official patch or fix is currently indicated in the advisory; operational controls are the recommended mitigation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-09-18T14:26:09.655Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-93685","vendor":"Red Hat"}]
Threat ID: 6aad527255bf5e2cf5282ffb
Added to database: 09/18/2026, 15:02:10 UTC
Last enriched: 09/18/2026, 15:16:46 UTC
Last updated: 09/19/2026, 03:40:30 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.