CVE-2026-92745

MEDIUM CVSS 3.1: 5.0 EPSS 0.14%
Updated Sep 22, 2026
Red Hat
Parameter Value
CVSS 5.0 (MEDIUM)
Type CWE-214
Vendor Red Hat
Public PoC No

A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when it is passed as a command-line argument to a helper script during the token validation process.

Successful exploitation could lead to the compromise of confidentiality, as the exposed token can be used to request access tokens.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)