Skip to main content

Threats Tagged 'cve-2026-59869'

View all threats tagged with 'cve-2026-59869'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-59869

Threats Tagged 'cve-2026-59869'

Click on any threat for detailed analysis and mitigation recommendations

Migration Toolkit for Applications (MTA) accelerates large-scale application modernization efforts across hybrid cloud environments on Red Hat OpenShift. This solution provides insight throughout the adoption process, at both the portfolio and application levels: inventory, assess, analyze, and manage applications for faster migration to OpenShift via the user interface.

Join the discussion

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.22.15. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:68550 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/

Join the discussion

Red Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments. Clusters and applications are all visible and managed from a single console—with security policy built in. This advisory contains the container images for Red Hat Advanced Cluster Management for Kubernetes, which add new features and enhancements, bug fixes, and updated container images. See the following Release Notes documentation, which will be updated shortly for this release, for additional details about this release: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.11/html-single/release_notes/index#acm-release-notes

Join the discussion

Red Hat Developer Hub (RHDH) versions prior to 1.9.9 contain a security vulnerability identified as CVE-2026-19534. Red Hat Developer Hub is an enterprise-grade, self-managed developer portal based on Backstage.io, supported on Kubernetes platforms including OpenShift. The advisory references a fix in version 1.9.9 that addresses this and other issues. No CVSS score is provided for this vulnerability.

Join the discussion

Red Hat Advanced Cluster Management for Kubernetes has a security advisory addressing multiple vulnerabilities including CVE-2026-41178. This update includes new features, bug fixes, and updated container images to improve security and functionality. The advisory highlights fixes for issues such as image override regressions and other security concerns. The update is rated as important by Red Hat Product Security and affects specific versions of the product. A patch is available to remediate these vulnerabilities.

Join the discussion

Red Hat Ansible Automation Platform 2.1 delivers an Ansible-first Red Hat Developer Hub user experience that simplifies the automation experience for Ansible users of all skill levels. The Ansible plug-ins provide curated content and features to accelerate Ansible learner onboarding and streamline Ansible use case adoption across your organization.

Join the discussion

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-controller: GitPython: Remote Code Execution via Git directory impersonation (CVE-2026-87817) * automation-controller: Job template enumeration via unauthenticated Bitbucket webhook oracle (CVE-2026-84717) * automation-controller: Command argument injection via SystemJob extra_vars (CVE-2026-84724) * automation-controller: Masked credential data disclosure via workflow job node artifact search (CVE-2026-84720) * automation-controller: Instance-group privilege escalation via workflow job template copy (CVE-2026-84719) * automation-controller: Audit log falsification via unrestricted X-Forwarded-For trust (CVE-2026-84718) * automation-controller: Mesh certificate issuance for arbitrary hostnames via install bundle (CVE-2026-84716) * automation-controller: Template injection via sanitize_jinja regex bypass (CVE-2026-84714) * automation-controller: Automation mesh topology disclosure via unauthenticated ping endpoint (CVE-2026-84712) * automation-controller: Arbitrary file read via Project scm_branch git argument injection (CVE-2026-84711) * automation-controller: Denial of service via credential type injector Jinja rendering (CVE-2026-84709) * automation-controller: Control-plane secret exposure via container group pod spec override (CVE-2026-84708) * automation-controller: Unauthorized job output disclosure via host filter query traversal (CVE-2026-84707) * automation-controller: Code execution via credential type environment-injector blocklist bypass (CVE-2026-84706) * automation-controller: Cross-tenant credential exposure via execution environment binding (CVE-2026-84703) * automation-controller: Cross-tenant execution privilege bypass via workflow job template node patch (CVE-2026-84692) * automation-controller: Secret key and database credential disclosure via format-string injection (CVE-2026-84691) * automation-controller: Cross-tenant job hijack via Bulk Job Launch node reference (CVE-2026-84689) * automation-controller: Credential token disclosure via notification template type-switch replay (CVE-2026-84686) * automation-controller: Privilege escalation via constructed inventory attachment (CVE-2026-84684) * automation-controller: Stored cross-site scripting via ANSI hyperlink sequence in job output (CVE-2026-84683) * automation-controller: Credential-use privilege escalation via organization Galaxy credential attachment (CVE-2026-84680) * automation-controller: Arbitrary environment variable injection via AWX_TASK_ENV setting (CVE-2026-84679) * automation-controller: Code execution via GALAXY_TASK_ENV environment variable injection (CVE-2026-84678) * automation-controller: Server-side request forgery via Thycotic Secret Server credential test (CVE-2026-84644) * automation-controller: Cross-organization credential exposure via Project signature-validation binding (CVE-2026-84643) * automation-controller: Instance-group privilege escalation via Schedule and workflow node attachment (CVE-2026-84638) * automation-controller: Remote code execution via Project scm_url git argument injection (CVE-2026-84502) * automation-controller: Survey password disclosure via validation error message (CVE-2026-84499) * automation-controller: Privilege escalation via provisioning-callback host-match bypass (CVE-2026-84474) * automation-controller: Instance-group privilege escalation via Bulk Job Launch permission check (CVE-2026-84470) * automation-controller: awx: Privilege escalation to OpenShift namespace via pod_spec_override injection in container groups (CVE-2026-75884) * automation-controller: Command-line argument injection via ad hoc command limit field (CVE-2026-71465) * automation-controller: Git argument-injection guard bypass via Schedule scm_branch prompt (CVE-2026-71464) * automation-controller: Stack trace disclosure via notification-template Jinja whitelist bypass (CVE-2026-71463) * automation-controller: Filesystem path-existence oracle via CUSTOM_VENV_PATHS validation (CVE-2026-71462) * automation-controller: Cross-tenant job event data exposure via missing RBAC check (CVE-2026-71459) * automation-controller: Cross-tenant resource enumeration via Named-URL 404 response oracle (CVE-2026-71458) * automation-controller: Unrestricted subscription and license information disclosure (CVE-2026-71460) * automation-controller: GitPython: Arbitrary code execution via command injection due to unguarded Git options (CVE-2026-67323) * automation-controller: GitPython: Co

Join the discussion

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-controller: GitPython: Remote Code Execution via Git directory impersonation (CVE-2026-87817) * automation-controller: Job template enumeration via unauthenticated Bitbucket webhook oracle (CVE-2026-84717) * automation-controller: Command argument injection via SystemJob extra_vars (CVE-2026-84724) * automation-controller: Masked credential data disclosure via workflow job node artifact search (CVE-2026-84720) * automation-controller: Instance-group privilege escalation via workflow job template copy (CVE-2026-84719) * automation-controller: Audit log falsification via unrestricted X-Forwarded-For trust (CVE-2026-84718) * automation-controller: Mesh certificate issuance for arbitrary hostnames via install bundle (CVE-2026-84716) * automation-controller: Template injection via sanitize_jinja regex bypass (CVE-2026-84714) * automation-controller: Automation mesh topology disclosure via unauthenticated ping endpoint (CVE-2026-84712) * automation-controller: Arbitrary file read via Project scm_branch git argument injection (CVE-2026-84711) * automation-controller: Denial of service via credential type injector Jinja rendering (CVE-2026-84709) * automation-controller: Control-plane secret exposure via container group pod spec override (CVE-2026-84708) * automation-controller: Unauthorized job output disclosure via host filter query traversal (CVE-2026-84707) * automation-controller: Code execution via credential type environment-injector blocklist bypass (CVE-2026-84706) * automation-controller: Cross-tenant credential exposure via execution environment binding (CVE-2026-84703) * automation-controller: Cross-tenant execution privilege bypass via workflow job template node patch (CVE-2026-84692) * automation-controller: Secret key and database credential disclosure via format-string injection (CVE-2026-84691) * automation-controller: Cross-tenant job hijack via Bulk Job Launch node reference (CVE-2026-84689) * automation-controller: Credential token disclosure via notification template type-switch replay (CVE-2026-84686) * automation-controller: Privilege escalation via constructed inventory attachment (CVE-2026-84684) * automation-controller: Stored cross-site scripting via ANSI hyperlink sequence in job output (CVE-2026-84683) * automation-controller: Credential-use privilege escalation via organization Galaxy credential attachment (CVE-2026-84680) * automation-controller: Arbitrary environment variable injection via AWX_TASK_ENV setting (CVE-2026-84679) * automation-controller: Server-side request forgery via Thycotic Secret Server credential test (CVE-2026-84644) * automation-controller: Cross-organization credential exposure via Project signature-validation binding (CVE-2026-84643) * automation-controller: Instance-group privilege escalation via Schedule and workflow node attachment (CVE-2026-84638) * automation-controller: Remote code execution via Project scm_url git argument injection (CVE-2026-84502) * automation-controller: Survey password disclosure via validation error message (CVE-2026-84499) * automation-controller: Unauthenticated scheduler-trigger endpoint exposure (regression) (CVE-2026-84486) * automation-controller: Privilege escalation via provisioning-callback host-match bypass (CVE-2026-84474) * automation-controller: Instance-group privilege escalation via Bulk Job Launch permission check (CVE-2026-84470) * automation-controller: GitPython: Arbitrary file read via TagReference.create() (CVE-2026-78679) * automation-controller: awx: Privilege escalation to OpenShift namespace via pod_spec_override injection in container groups (CVE-2026-75884) * automation-controller: Command-line argument injection via ad hoc command limit field (CVE-2026-71465) * automation-controller: Git argument-injection guard bypass via Schedule scm_branch prompt (CVE-2026-71464) * automation-controller: Stack trace disclosure via notification-template Jinja whitelist bypass (CVE-2026-71463) * automation-controller: Filesystem path-existence oracle via CUSTOM_VENV_PATHS validation (CVE-2026-71462) * automation-controller: Cross-tenant job event data exposure via missing RBAC check (CVE-2026-71459) * automation-controller: Cross-tenant resource enumeration via Named-URL 404 response oracle (CVE-2026-71458) * automation-controller: Unrestricted subscription and license information disclosure (CVE-2026-71460) * automation-controller: GitPython: Command Injection via Git option

Join the discussion

This update includes the following RPMs: golang1.25: * golang1.25-1.25.11-2.hum1 (aarch64, x86_64) * golang1.25-bin-1.25.11-2.hum1 (aarch64, x86_64) * golang1.25-docs-1.25.11-2.hum1 (noarch) * golang1.25-misc-1.25.11-2.hum1 (noarch) * golang1.25-src-1.25.11-2.hum1 (noarch) * golang1.25-tests-1.25.11-2.hum1 (noarch) * golang1.25-1.25.11-2.hum1.src (src)

Join the discussion

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.19.48. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:68540 Security Fix(es): * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820) * golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499) * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli.

Join the discussion

Showing 1 to 10 of 48 results

Filters:Tag: cve-2026-59869
Page 1 of 5
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses