RedHat Multicluster Observability Addon: Auth Bypass on Debug Endpoint
CVE-2026-93685 Published on September 18, 2026
Multicluster-observability-addon: multicluster-observability-addon: possible unauthenticated debug/metrics endpoint via cmdfactory.newcontrollercommandconfig (confirmed exposed by engineering)
A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details, after completing a basic encrypted connection. This vulnerability does not enable direct remote code execution.
Vulnerability Analysis
Timeline
Reported to Red Hat.
Made public. 79 days later.
Weakness Type
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2026-93685 has been classified to as an Information Disclosure vulnerability or weakness.
Products Associated with CVE-2026-93685
Want to know whenever a new CVE is published for Red Hat Acm? stack.watch will email you.