AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-50236

HIGH · CVSS 7.4 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

An authenticated Server-Side Request Forgery (SSRF) vulnerability exists in the OpenShift Console Dev Console webhook helpers, allowing attackers to exploit user-supplied target URLs that are fetched server-side without proper validation. This flaw enables arbitrary endpoint targeting and full response reflection, potentially exposing sensitive data from the console pod's privileged network position. Organizations using OpenShift should prioritize patching this vulnerability to mitigate the risk of unauthorized access and data leakage.

CVE
CVE-2026-50236
Severity
HIGH
CVSS
7.4
EPSS
0.21%

Original NVD Description

An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.