{"id":"CVE-2026-93685","title":"A flaw was found in the multicluster-observability-addon","summary":"A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensit…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","cwe":["CWE-200"],"vendor":"Red Hat","product":"redhat-user-workloads/multicluster-observability-addon-acm-213","affected":["redhat-user-workloads/multicluster-observability-addon-acm-213","rhacm2/acm-multicluster-observability-addon-rhel9 (all versions)"],"published":"2026-09-18","updated":"2026-09-21","sourceUpdated":"2026-09-21T21:17:19.317","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93685","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-93685","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2518377","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-21T19:40:03.151609Z"},"epss":0.00362,"epssPercentile":0.29879,"ingestedAt":"2026-09-18T15:44:31.580Z","slug":"CVE-2026-93685","body":"## Overview\n\nA flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details, after completing a basic encrypted connection. This vulnerability does not enable direct remote code execution.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}