Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76594

Опубликовано: 02 сент. 2026
Источник: redhat
CVSS3: 8.1

Описание

A flaw was found in advisor-backend. A network-adjacent unauthenticated attacker could exploit a vulnerability in the /private/import_content/ endpoint, which lacks proper authentication and permission checks. This allows the attacker to overwrite the global Advisor rule, resolution, and playbook catalogue. When combined with another vulnerability involving unsafe YAML deserialization, this could lead to arbitrary code execution on affected systems.

Отчет

This is an Important vulnerability as an unauthenticated, network-adjacent attacker can overwrite the global Red Hat Advisor rule catalogue. This flaw, when chained with a separate unsafe YAML deserialization vulnerability, could lead to remote code execution on customer hosts by injecting malicious Ansible playbooks. The affected endpoint is exposed on the same listener as the public API, increasing the risk in standard deployments.

Меры по смягчению последствий

Restrict network access to the /private/import_content/ endpoint of the advisor-backend service. Configure network policies or firewall rules to limit connections to this path to only trusted internal networks or localhost, preventing unauthenticated external access. This will reduce the attack surface by ensuring only authorized internal services can interact with the content import functionality. If the service is reloaded or restarted, ensure the network restrictions remain in effect.

Дополнительная информация

Статус:

Important
Дефект:
CWE-306
https://bugzilla.redhat.com/show_bug.cgi?id=2519645advisor-backend: advisor-backend: Unauthenticated /private/import_content/ endpoint allows global rule-catalogue overwrite

8.1 High

CVSS3

8.1 High

CVSS3

Уязвимость CVE-2026-76594