CVE WATCH / VULNERABILITY DETAIL

CVE-2026-75887

HIGHCVSS 7.5NVD feed

Published 23 September 2026 · tracked since 24 September 2026

Description

A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive `*.json` files from the pod filesystem, including

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-75887 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-75887

HIGHCVSS 7.5NVD feed

Published 23 September 2026 · tracked since 24 September 2026

Description

A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive `*.json` files from the pod filesystem, including

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]