Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this issue, restrict network access to the pods running the `multicluster-observability-addon` to only trusted internal components. Implement network policies within your Kubernetes environment to limit inbound connections to the affected pods on ports 6060 and 8443 from untrusted sources. This operational control reduces the attack surface by preventing unauthorized access to the unauthenticated debug endpoints.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details, after completing a basic encrypted connection. This vulnerability does not enable direct remote code execution. | |
| Title | Multicluster-observability-addon: multicluster-observability-addon: possible unauthenticated debug/metrics endpoint via cmdfactory.newcontrollercommandconfig (confirmed exposed by engineering) | |
| First Time appeared |
Redhat
Redhat acm |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:/a:redhat:acm:2 | |
| Vendors & Products |
Redhat
Redhat acm |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-18T14:53:02.159Z
Reserved: 2026-09-18T14:26:09.655Z
Link: CVE-2026-93685
No data.
Status : Received
Published: 2026-09-18T15:17:22.950
Modified: 2026-09-18T15:17:22.950
Link: CVE-2026-93685
No data.
OpenCVE Enrichment
No data.
