Insights-client Exposes Pull-Secret via Pod Log Leakage
CVE-2026-71474 Published on August 11, 2026
Insights-client-rhel9: insights-client: pull-secret bearer token written to logs on non-200 ccx response
A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-lived credential. This information disclosure could grant unauthorized access to Red Hat cloud services.
Vulnerability Analysis
CVE-2026-71474 is exploitable with local system access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Timeline
Reported to Red Hat.
Made public. 5 days later.
Weakness Type
Insertion of Sensitive Information into Log File
Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
Products Associated with CVE-2026-71474
Want to know whenever a new CVE is published for Red Hat Acm? stack.watch will email you.
Affected Versions
Red Hat Advanced Cluster Management for Kubernetes 2.11:- Version 1787688993 and below * is unaffected.
- Version 1787259125 and below * is unaffected.
- Version 1786882244 and below * is unaffected.
- Version 1787238585 and below * is unaffected.
- Version 1787184541 and below * is unaffected.
- Version 1787227689 and below * is unaffected.