Skip to main content

CVE-2026-93685: Exposure of Sensitive Information to an Unauthorized Actor in Red Hat Red Hat Advanced Cluster Management for Kubernetes 2

0
Medium
VulnerabilityCVE-2026-93685cvecve-2026-93685
Published: 09/18/2026 (09/18/2026, 14:48:20 UTC)
Source: CVE Database V5
Vendor/Project: Red Hat
Product: Red Hat Advanced Cluster Management for Kubernetes 2

Description

A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details, after completing a basic encrypted connection. This vulnerability does not enable direct remote code execution.

CVSS v3.1

Score 5.4medium

Attack Vector
Adjacent Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
Low
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Affected software

Red Hat

Red Hat Advanced Cluster Management for Kubernetes 2

Red Hat

Red Hat Advanced Cluster Management for Kubernetes 2

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/18/2026, 15:16:46 UTC

Technical Analysis

A flaw in the multicluster-observability-addon of Red Hat Advanced Cluster Management for Kubernetes 2 allows remote attackers to access debug endpoints without authentication because of a misconfiguration in the underlying addon-framework library. This unauthorized access exposes sensitive operational information including goroutine, heap, and command-line details after completing a trivial TLS handshake. Although this vulnerability does not enable direct remote code execution, it increases the attack surface by providing attackers with reconnaissance data. The vulnerability affects the debug endpoints exposed on port 8443 and port 6060. Red Hat recommends restricting network access to the pods running the multicluster-observability-addon to trusted internal components and applying network policies to block untrusted inbound connections to these ports.

Potential Impact

The vulnerability allows unauthorized disclosure of sensitive operational information such as goroutine stacks, heap data, and command-line arguments. This information leakage can aid attackers in reconnaissance activities but does not allow direct remote code execution or integrity compromise. The impact is limited to confidentiality and availability with low severity on confidentiality and availability, and no impact on integrity.

Mitigation Recommendations

Red Hat advises restricting network access to the pods running the multicluster-observability-addon to trusted internal components only. Implement Kubernetes network policies to limit inbound connections on ports 6060 and 8443 to trusted sources, thereby preventing unauthorized access to the unauthenticated debug endpoints. No official patch or fix is currently indicated in the advisory; operational controls are the recommended mitigation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
redhat
Date Reserved
2026-09-18T14:26:09.655Z
Cvss Version
3.1
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-93685","vendor":"Red Hat"}]

Threat ID: 6aad527255bf5e2cf5282ffb

Added to database: 09/18/2026, 15:02:10 UTC

Last enriched: 09/18/2026, 15:16:46 UTC

Last updated: 09/19/2026, 03:40:30 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses