{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/openshift-console/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:redhat:openshift_console:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-75886"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenShift Console"],"_cs_severities":["high"],"_cs_tags":["vulnerability","cloud-native","identity-management"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2026-75886 affects the Red Hat OpenShift Console, specifically within the CatalogdHandler component. The vulnerability arises from a lack of mandatory authentication checks coupled with the improper forwarding of the \u003ccode\u003eopenshift-session-token\u003c/code\u003e cookie. This configuration error enables an unauthenticated remote attacker to interact directly with the in-cluster catalogd service. By successfully leveraging this flaw, an attacker can exfiltrate sensitive internal operator-catalog index information. Furthermore, the vulnerability provides a relay vector into the \u003ccode\u003eopenshift-catalogd\u003c/code\u003e namespace, potentially exposing cluster-internal services that are intended to be shielded from external access. This is a critical risk for organizations relying on OpenShift for container orchestration, as it facilitates unauthorized reconnaissance and potential lateral movement into internal cluster management components.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to gain unauthorized access to internal operator-catalog index information. Beyond the disclosure of sensitive infrastructure metadata, the ability to relay requests into the \u003ccode\u003eopenshift-catalogd\u003c/code\u003e namespace may allow an attacker to reach or interact with other internal cluster-catalog components that lack secondary authentication, potentially escalating access within the internal network segment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web application logs for unauthorized POST or GET requests to catalog-related API endpoints originating from outside the cluster internal network.\u003c/li\u003e\n\u003cli\u003eReview cluster ingress and network policy configurations to limit access to the OpenShift Console and ensure that internal services like catalogd are not exposed to external traffic.\u003c/li\u003e\n\u003cli\u003eUpdate OpenShift Console to the latest patched version provided by Red Hat as soon as the security advisory for CVE-2026-75886 is released.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T00:45:21Z","date_published":"2026-09-24T00:45:21Z","id":"https://feed.craftedsignal.io/briefs/2026-09-openshift-console-cve/","summary":"A misconfiguration in the OpenShift Console CatalogdHandler allows unauthenticated remote attackers to leak internal operator-catalog data and relay requests into the catalogd namespace.","title":"Unauthenticated Information Disclosure in OpenShift Console via CatalogdHandler","url":"https://feed.craftedsignal.io/briefs/2026-09-openshift-console-cve/"}],"language":"en","title":"CraftedSignal Threat Feed - OpenShift Console","version":"https://jsonfeed.org/version/1.1"}