Critical severity9.1NVD Advisory· Published May 26, 2021· Updated Jun 17, 2026
CVE-2018-10866
CVE-2018-10866
Description
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to remove a "system" file, that is an xml file with host related information, not belonging to him.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:redhat:certification:7.0:*:*:*:*:*:*:*
- redhat/redhat-certificationdescription
Patches
Vulnerability mechanics
References
2- access.redhat.com/security/cve/CVE-2018-10866nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.