THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-71475 (MEDIUM 6.8) — A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the request path without proper validat

[NVD] CVE-2026-71475 (MEDIUM 6.8) — A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the request path without proper validat

mednvdPublished 2026-08-11

CVE-2026-71475 CVSS: 6.8 MEDIUM Published: 2026-08-11T20:18:45.673

A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the request path without proper validation or URL encoding. This vulnerability allows a mal

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-71475