Impact
A local threat actor who has membership in the "haclient" group can run the pcs host auth --token command and cause the pcsd daemon to read the contents of any file on the system that is no larger than 256 bytes. The data is read with root privileges and can be sent back over the cluster to the attacker. Because the attacker can obtain arbitrary file contents, secrets such as API keys, tokens, or configuration files become available, leading to a confidentiality breach. This flaw is a local privilege escalation that enables read access to sensitive data without additional authentication or network involvement.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux 8, 9, and 10 as well as Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 16.2, and Red Hat OpenStack Platform 17.1. No specific sub‑versions or patch levels are listed, so the entire product lines listed are potentially impacted.
Risk and Exploitability
The CVSS score is 6.5, indicating moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, so there is no evidence of active exploitation at this time. The attack vector is local; an attacker must have local access and a haclient group membership. Once these prerequisites are met, exploitation is straightforward, reading files up to 256 bytes in size and exfiltrating them through cluster communication. The risk is therefore limited to environments where the haclient group is overly permissive.
OpenCVE Enrichment