Description
A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details, after completing a basic encrypted connection. This vulnerability does not enable direct remote code execution.
Published: 2026-09-18
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure via unauthenticated debug endpoint
Action: Limit Access
AI Analysis

Impact

The flaw in multicluster-observability-addon allows an attacker to reach a debug endpoint without authentication because the addon‑framework library is misconfigured. Accessing this endpoint exposes operational details such as goroutine listings, heap snapshots, and command-line arguments, which can aid further reconnaissance. The vulnerability does not provide a path to remote code execution.

Affected Systems

This issue affects Red Hat Advanced Cluster Management for Kubernetes 2. No specific sub‑version is listed, so all versions of product 2 are potentially impacted.

Risk and Exploitability

At a CVSS score of 5.4, the vulnerability presents moderate risk, and the EPSS score of <1% indicates a low but non‑zero likelihood of exploitation, with no listing in the CISA KEV catalog. The public documentation shows that the addon provides a debug interface that can be accessed without authentication; while the exact ports are not explicitly documented, the recommended network policy targets ports 6060 and 8443, suggesting that these are the listening endpoints. Therefore, an attacker would need to reach the affected pods over the cluster network, targeting those ports if present, to trigger the information disclosure. The scope is limited to the pods within the cluster, and no remote code execution is possible.

Generated by OpenCVE AI on September 19, 2026 at 19:08 UTC.

Remediation

Vendor Workaround

To mitigate this issue, restrict network access to the pods running the `multicluster-observability-addon` to only trusted internal components. Implement network policies within your Kubernetes environment to limit inbound connections to the affected pods on ports 6060 and 8443 from untrusted sources. This operational control reduces the attack surface by preventing unauthorized access to the unauthenticated debug endpoints.


OpenCVE Recommended Actions

  • Restrict network access to the multicluster‑observability‑addon pods to trusted internal components, implementing network policies that block inbound connections on ports 6060 and 8443 from untrusted sources.
  • Apply the latest Red Hat updates or patches that address the misconfiguration in the addon‑framework library as soon as they become available.
  • Reconfigure the addon‑framework components to enforce authentication on debug endpoints, ensuring that such interfaces are protected by the cluster’s authentication controls.

Generated by OpenCVE AI on September 19, 2026 at 19:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat advanced Cluster Management For Kubernetes
Vendors & Products Redhat advanced Cluster Management For Kubernetes

Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 18 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details, after completing a basic encrypted connection. This vulnerability does not enable direct remote code execution.
Title Multicluster-observability-addon: multicluster-observability-addon: possible unauthenticated debug/metrics endpoint via cmdfactory.newcontrollercommandconfig (confirmed exposed by engineering)
First Time appeared Redhat
Redhat acm
Weaknesses CWE-200
CPEs cpe:/a:redhat:acm:2
Vendors & Products Redhat
Redhat acm
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}


Subscriptions

Redhat Acm Advanced Cluster Management For Kubernetes
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-21T20:51:26.819Z

Reserved: 2026-09-18T14:26:09.655Z

Link: CVE-2026-93685

cve-icon Vulnrichment

Updated: 2026-09-21T19:40:05.555Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T15:17:22.950

Modified: 2026-09-21T21:17:19.317

Link: CVE-2026-93685

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-18T14:37:24Z

Links: CVE-2026-93685 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor