Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 1.9%top 22%

Red Hat Security Advisory: Red Hat Web Terminal Operator 1.12.0 release.

0
High
Published: 04/23/2026 (04/23/2026, 18:54:04 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The Web Terminal provides a way to access a fully in-browser terminal emulator within the OpenShift Console. Command-line tools for interacting with the OpenShift cluster are pre-installed.

Affected software

Affected versions
Red HatRed Hat OpenShift Container PlatformRed Hat OpenShift Container Platform 4.18amd64registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9@sha256:1a1093a3f8b38306f4fc9cf02f2a91c07c1f0c577615d3a4106505333041a52c_amd64Red Hat Enterprise LinuxRed Hat Enterprise Linux AppStream EUS (v. 10.0)Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)srcNetwork Observability (NETOBSERV)Network Observability (NETOBSERV) 1.11.1registry.redhat.io/network-observability/network-observability-flowlogs-pipeline-rhel9@sha256:7e2463af3ff443c98adf0bbfe349c7d9da90c8de34892e41b46627f30623b47a_amd64Red Hat QuayRed Hat Quay 3.9registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:8c7d45b2b41967720762c47cace1a1467c770e310e840c66de140da510e6f7bc_amd64Red Hat OpenStack Services on OpenShiftRed Hat OpenStack Services on OpenShift 18.0registry.redhat.io/rhoso-operators/barbican-rhel9-operator@sha256:93cca70ca2d64dff06450c3e39f6b69c5287e57b3a4465fc31a45ce6247e4aae_amd64Red Hat Web TerminalRed Hat Web Terminal 1.12registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:0d1d6a7ab4d79ce38526b5cba5b2bf7cfcb4229384115e71770a4f47db5575e2_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 08:40:43 UTC

Technical Analysis

The Red Hat Web Terminal Operator allows users to access a terminal emulator directly in the OpenShift Console, facilitating command-line interaction with the cluster. The security advisory RHSA-2026:10225 lists multiple CVEs affecting this operator, including CVE-2025-61726 and others. The advisory announces the release of version 1.12.0 but does not specify any fixes or patches addressing these vulnerabilities. The affected environment is OpenShift Container Platform 4.17 or later. No cloud service remediation applies as this is not a cloud service. No known exploits have been reported. The advisory provides references but no explicit remediation instructions or patches.

Potential Impact

The vulnerabilities affect the Red Hat Web Terminal Operator, potentially impacting the security of in-browser terminal access to OpenShift clusters. The advisory classifies the severity as high but does not provide detailed impact descriptions or exploitation evidence. No known exploits in the wild have been reported. The lack of explicit patch or fix information suggests that the vulnerabilities may still be present in the released version 1.12.0 or that the advisory is primarily informational about the release.

Mitigation Recommendations

The vendor advisory does not specify any patches or fixes for the listed vulnerabilities. Users are advised to install the Web Terminal Operator from OpenShift OperatorHub on OpenShift Container Platform 4.17 or higher as per the advisory. Patch status is not yet confirmed — check the vendor advisory at https://access.redhat.com/errata/RHSA-2026:10225 for current remediation guidance. No vendor instructions indicate that no action is required or that the issue is already mitigated.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:10225
Cve Count
5
Additional Cves
["CVE-2025-61729","CVE-2025-68121","CVE-2026-25679","CVE-2026-27137"]
Cvss Version
null

Threat ID: 6a16096de29bf47b50634278

Added to database: 05/26/2026, 20:58:21 UTC

Last enriched: 07/30/2026, 08:40:43 UTC

Last updated: 07/31/2026, 21:28:47 UTC

Views: 94

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:21657https://access.redhat.com/security/cve/CVE-2025-61726https://access.redhat.com/security/cve/CVE-2026-25679https://access.redhat.com/security/cve/CVE-2026-27143https://access.redhat.com/security/cve/CVE-2026-27144https://access.redhat.com/security/cve/CVE-2026-29063https://access.redhat.com/security/cve/CVE-2026-33186https://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:17040https://access.redhat.com/security/updates/classification/#important241846224344312434432243711124453562455470Canonical URLhttps://access.redhat.com/errata/RHSA-2026:6428https://access.redhat.com/security/cve/CVE-2025-61728https://access.redhat.com/security/cve/CVE-2025-61729https://access.redhat.com/security/cve/CVE-2025-68121https://access.redhat.com/security/cve/CVE-2026-25639https://access.redhat.com/security/cve/CVE-2026-26960https://docs.openshift.com/container-platform/latest/observability/network_observability/network-observability-operator-release-notes.htmlCanonical URLhttps://access.redhat.com/errata/RHSA-2026:23361https://access.redhat.com/security/cve/CVE-2025-62718https://access.redhat.com/security/cve/CVE-2026-2377https://access.redhat.com/security/cve/CVE-2026-32280https://access.redhat.com/security/cve/CVE-2026-32281https://access.redhat.com/security/cve/CVE-2026-32282https://access.redhat.com/security/cve/CVE-2026-32589https://access.redhat.com/security/cve/CVE-2026-32590https://access.redhat.com/security/cve/CVE-2026-33894https://access.redhat.com/security/cve/CVE-2026-34986https://access.redhat.com/security/cve/CVE-2026-39892https://access.redhat.com/security/cve/CVE-2026-40192https://access.redhat.com/security/cve/CVE-2026-40895https://access.redhat.com/security/cve/CVE-2026-42033https://access.redhat.com/security/cve/CVE-2026-42035https://access.redhat.com/security/cve/CVE-2026-42039https://access.redhat.com/security/cve/CVE-2026-42041https://access.redhat.com/security/cve/CVE-2026-42043https://access.redhat.com/errata/RHSA-2026:11747https://catalog.redhat.com/software/containers/searchCanonical URLhttps://access.redhat.com/errata/RHSA-2026:10225https://access.redhat.com/security/cve/CVE-2026-27137https://redhat.atlassian.net/browse/WTO-360https://redhat.atlassian.net/browse/WTO-362https://redhat.atlassian.net/browse/WTO-365https://redhat.atlassian.net/browse/WTO-370https://redhat.atlassian.net/browse/WTO-380https://redhat.atlassian.net/browse/WTO-385https://redhat.atlassian.net/browse/WTO-389Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses