Description
A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when it is passed as a command-line argument to a helper script during the token validation process. Successful exploitation could lead to the compromise of confidentiality, as the exposed token can be used to request access tokens.
Published: 2026-09-18
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Assess
AI Analysis

Impact

This vulnerability enables a local attacker to glean a Red Hat Subscription Management offline token that is exposed in the command line of a helper script during token validation. The flaw occurs when the token is passed as a process argument, allowing process metadata inspection to retrieve the token value. The exposed token can be used to obtain access tokens, thereby compromising confidentiality of subscription data. This weakness corresponds to CWE-214, involving improper removal of sensitive information from process metadata.

Affected Systems

Affected systems include Red Hat Enterprise Linux 10 and Red Hat Enterprise Linux 9. The vulnerability is present in the cockpit‑machines service that ships with these operating system releases.

Risk and Exploitability

The vulnerability is rated with a CVSS score of 5, indicating moderate severity. EPSS data is not available, so the probability of exploitation is uncertain. It is not listed in the CISA KEV catalog. The likely attack vector is local, requiring the attacker to have the ability to inspect process metadata, which typically requires privileged access or compromise of a local account. With this access, the attacker can expose the offline token and use it to request new access tokens.

Generated by OpenCVE AI on September 19, 2026 at 12:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict local account permissions so that only trusted users can inspect process metadata
  • Update cockpit‑machines to a version that removes the offline token from command‑line arguments, or apply any vendor‑issued patch when available
  • Apply the principle of least privilege to processes that handle subscription tokens, ensuring they run with minimal rights

Generated by OpenCVE AI on September 19, 2026 at 12:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when it is passed as a command-line argument to a helper script during the token validation process. Successful exploitation could lead to the compromise of confidentiality, as the exposed token can be used to request access tokens.
Title Cockpit-machines: cockpit-machines: information disclosure of rhsm offline token via process arguments
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-214
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-22T19:26:31.871Z

Reserved: 2026-09-16T18:40:00.345Z

Link: CVE-2026-92745

cve-icon Vulnrichment

Updated: 2026-09-22T15:17:58.333Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T18:18:16.410

Modified: 2026-09-22T16:18:12.433

Link: CVE-2026-92745

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-18T16:35:00Z

Links: CVE-2026-92745 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:25:01Z

Weaknesses
  • CWE-214

    Invocation of Process Using Visible Sensitive Information