OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-75887

HIGH · CVSS 7.5 EPSS 0.51% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

A path traversal vulnerability in the OpenShift console allows unauthenticated attackers to manipulate the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint, potentially exposing sensitive JSON files from the pod filesystem, such as plugin manifests and configuration files. This high-severity flaw could lead to unauthorized access to critical information, making it essential for organizations using OpenShift to prioritize immediate remediation efforts. Security teams should focus on patching this vulnerability to protect against potential data breaches and exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75887
Severity
HIGH
CVSS
7.5
EPSS
0.51%

Original NVD Description

A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive `*.json` files from the pod filesystem, including plugin manifests and configuration files. Furthermore, this flaw can enable path traversal against registered dynamic-plugin backends.