Skip to content
CVE Alert: CVE-2026-75887 – Red Hat

CVE Alert: CVE-2026-75887 – Red Hat

Redpacketsecurity admin September 23, 2026

A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive `*.json` files from the pod filesystem, including plugin manifests and configuration files. Furthermore, this flaw can enable path traversal against registered dynamic-plugin backends.

**Risk verdict:** High-priority exposure: unauthenticated remote access can disclose sensitive files, but KEV, SSVC, PoC and EPSS indicators were not supplied, so active exploitation urgency cannot be confirmed.

**Why this matters:** Configuration and plugin data can reveal internal services, deployment details or credentials if these are present in readable files. Access to registered plugin backends could broaden the information exposed, although the supplied impact indicates no direct modification or service disruption.

**Most likely attack path:** An attacker needs network reachability to the console endpoint; low complexity, no account and no user action make probing straightforward. Scope is unchanged, so this does not itself establish access beyond the affected service, but exposed backend data may inform later attacks.

**Who is most exposed:** Clusters with internet-accessible or broadly reachable administration consoles face the greatest exposure; internal consoles remain at risk from compromised or untrusted network footholds.

Alert on unusual requests to locale-resource handling, especially traversal-like or encoded path components.

Review console access logs for unauthenticated bursts, atypical query values and repeated file-name probing.

Check egress and backend logs for console-originated requests to unexpected plugin services.

Investigate suspicious reads alongside subsequent authentication attempts using discovered credentials.

Mitigation and prioritisation:

Confirm affected deployments and apply the vendor-fixed build promptly; validate the fix before broad rollout.

Restrict console access to trusted networks and approved administrative paths while patching.

No suitable workaround is identified in the supplied information; do not rely on filtering alone.

Use normal change controls, but expedite emergency review if exposure is public or exploitation indicators emerge.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

CWE Weaknesses (1)

Platforms (1)

Vulnerabilities (1)