Medium severity6.8NVD Advisory· Published Aug 11, 2026· Updated Sep 5, 2026
CVE-2026-71475
CVE-2026-71475
Description
A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the request path without proper validation or URL encoding. This vulnerability allows a malicious spoke to redirect authenticated requests to unintended API endpoints, potentially leading to information disclosure or unauthorized access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
7- access.redhat.com/security/cve/CVE-2026-71475nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
- access.redhat.com/errata/RHSA-2026:60386nvd
- access.redhat.com/errata/RHSA-2026:60388nvd
- access.redhat.com/errata/RHSA-2026:60389nvd
- access.redhat.com/errata/RHSA-2026:60390nvd
- access.redhat.com/errata/RHSA-2026:60391nvd
News mentions
0No linked articles in our index yet.