High severity7.1NVD Advisory· Published Aug 11, 2026· Updated Sep 5, 2026
CVE-2026-71474
CVE-2026-71474
Description
A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-lived credential. This information disclosure could grant unauthorized access to Red Hat cloud services.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
8- access.redhat.com/security/cve/CVE-2026-71474nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
- access.redhat.com/errata/RHSA-2026:60386nvd
- access.redhat.com/errata/RHSA-2026:60387nvd
- access.redhat.com/errata/RHSA-2026:60388nvd
- access.redhat.com/errata/RHSA-2026:60389nvd
- access.redhat.com/errata/RHSA-2026:60390nvd
- access.redhat.com/errata/RHSA-2026:60391nvd
News mentions
0No linked articles in our index yet.