Loading market data...
← Back to CVE feed

CVE-2026-93685

MEDIUM CVSS 5.4 View on NVD ↗

Description

A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details, after completing a basic encrypted connection. This vulnerability does not enable direct remote code execution.

CVSS Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Published: Sep 18, 2026 15:17 UTC Modified: Sep 18, 2026 19:06 UTC