RedHat Multicluster Observability Addon: Auth Bypass on Debug Endpoint
CVE-2026-93685 Published on September 18, 2026

Multicluster-observability-addon: multicluster-observability-addon: possible unauthenticated debug/metrics endpoint via cmdfactory.newcontrollercommandconfig (confirmed exposed by engineering)
A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details, after completing a basic encrypted connection. This vulnerability does not enable direct remote code execution.

NVD

Vulnerability Analysis

Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
NONE
Availability Impact:
LOW

Timeline

Reported to Red Hat.

Made public. 79 days later.

Weakness Type

What is an Information Disclosure Vulnerability?

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CVE-2026-93685 has been classified to as an Information Disclosure vulnerability or weakness.


Products Associated with CVE-2026-93685

Want to know whenever a new CVE is published for Red Hat Acm? stack.watch will email you.

 

Affected Versions

Red Hat Advanced Cluster Management for Kubernetes 2: Red Hat Advanced Cluster Management for Kubernetes 2: