THREAT OPS › Threat News › [NVD] CVE-2026-71475 (MEDIUM 6.8) — A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the request path without proper validat
[NVD] CVE-2026-71475 (MEDIUM 6.8) — A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the request path without proper validat
CVE-2026-71475 CVSS: 6.8 MEDIUM Published: 2026-08-11T20:18:45.673
A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the request path without proper validation or URL encoding. This vulnerability allows a mal
Indicators of compromise
- CVE-2026-71475cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-71475