Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76595

Опубликовано: 02 сент. 2026
Источник: redhat

Описание

A flaw was found in advisor-backend. Multiple code paths within the application deserialize YAML (YAML Ain't Markup Language) with an unsafe full Loader, which can instantiate arbitrary Python objects via YAML tags. An unauthenticated remote attacker can exploit this by submitting specially crafted YAML input, leading to remote code execution (RCE) within the advisor-backend pod. This compromise could allow access to shared database credentials and impact all tenants.

Отчет

This Critical vulnerability in Red Hat Insights advisor-backend enables unauthenticated remote code execution. An attacker can exploit an unsafe YAML deserialization flaw, chained with an unauthenticated content import path, to execute arbitrary code within the multi-tenant advisor-backend pod. This allows for compromise of shared database credentials and tenant data, justifying the Critical impact due to the unauthenticated RCE.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Critical
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2519653advisor-backend: Unsafe YAML deserialization of associate-editable Task playbook (yaml.Loader)