Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
To mitigate this issue, restrict network access to the pods running the `multicluster-observability-addon` to only trusted internal components. Implement network policies within your Kubernetes environment to limit inbound connections to the affected pods on ports 6060 and 8443 from untrusted sources. This operational control reduces the attack surface by preventing unauthorized access to the unauthenticated debug endpoints.
Sat, 19 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 18 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details, after completing a basic encrypted connection. This vulnerability does not enable direct remote code execution. | |
| Title | Multicluster-observability-addon: multicluster-observability-addon: possible unauthenticated debug/metrics endpoint via cmdfactory.newcontrollercommandconfig (confirmed exposed by engineering) | |
| First Time appeared |
Redhat
Redhat acm |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:/a:redhat:acm:2 | |
| Vendors & Products |
Redhat
Redhat acm |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-18T14:53:02.159Z
Reserved: 2026-09-18T14:26:09.655Z
Link: CVE-2026-93685
No data.
Status : Awaiting Analysis
Published: 2026-09-18T15:17:22.950
Modified: 2026-09-18T19:06:08.407
Link: CVE-2026-93685
OpenCVE Enrichment
Updated: 2026-09-18T23:45:15Z