CVE-2026-96577: Missing Authentication for Critical Function in Red Hat Assisted Installer for Red Hat OpenShift Container Platform 2
A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the local system. An unauthenticated attacker on an adjacent network can connect to the exposed service to push tampered container images, delete cached images, or access mirrored content.
AI Analysis
Technical Summary
The vulnerability CVE-2026-96577 affects the oc-mirror tool used in the Red Hat Assisted Installer for Red Hat OpenShift Container Platform 2. During mirroring operations, the local cache registry is exposed on all network interfaces without authentication or encryption, rather than being restricted to the local system. This exposure enables an unauthenticated attacker on a network adjacent to the target to connect to the registry service and manipulate container images by pushing malicious content, deleting cached images, or accessing mirrored data.
Potential Impact
An unauthenticated attacker on an adjacent network can exploit this vulnerability to push malicious container images, delete cached images, or access mirrored content without authorization. This could lead to integrity compromise of container images used in deployments, potentially resulting in the execution of tampered or malicious containers. The confidentiality of mirrored content is also at risk. Availability impact is not indicated.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory at https://access.redhat.com/security/cve/CVE-2026-96577 for current remediation guidance. Until a fix is applied, restrict network access to the local cache registry to trusted hosts only, for example by firewalling or network segmentation, to prevent unauthorized access from adjacent networks.
CVE-2026-96577: Missing Authentication for Critical Function in Red Hat Assisted Installer for Red Hat OpenShift Container Platform 2
Description
A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the local system. An unauthenticated attacker on an adjacent network can connect to the exposed service to push tampered container images, delete cached images, or access mirrored content.
CVSS v3.1
Score 7.1high
Affected software
Red Hat
Assisted Installer for Red Hat OpenShift Container Platform 2
Red Hat
Red Hat OpenShift Container Platform 4
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-96577 affects the oc-mirror tool used in the Red Hat Assisted Installer for Red Hat OpenShift Container Platform 2. During mirroring operations, the local cache registry is exposed on all network interfaces without authentication or encryption, rather than being restricted to the local system. This exposure enables an unauthenticated attacker on a network adjacent to the target to connect to the registry service and manipulate container images by pushing malicious content, deleting cached images, or accessing mirrored data.
Potential Impact
An unauthenticated attacker on an adjacent network can exploit this vulnerability to push malicious container images, delete cached images, or access mirrored content without authorization. This could lead to integrity compromise of container images used in deployments, potentially resulting in the execution of tampered or malicious containers. The confidentiality of mirrored content is also at risk. Availability impact is not indicated.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory at https://access.redhat.com/security/cve/CVE-2026-96577 for current remediation guidance. Until a fix is applied, restrict network access to the local cache registry to trusted hosts only, for example by firewalling or network segmentation, to prevent unauthorized access from adjacent networks.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-09-23T13:30:40.232Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-96577","vendor":"Red Hat"}]
Threat ID: 6abe7499a43b0b3b89bd1d35
Added to database: 10/01/2026, 14:56:25 UTC
Last enriched: 10/01/2026, 15:25:12 UTC
Last updated: 10/01/2026, 19:46:47 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.