← All Advisories

CVE-2026-96577

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-96577

Key Details

CVECVE-2026-96577
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-10-01
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
CVSS Proseattack vector is adjacent; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is low; integrity impact is high; availability impact is none.
Affected productsRed Hat Red Hat OpenShift Container Platform 4
Classified asCWE-306 (Missing Authentication for Critical Function)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat OpenShift Container Platform 4
SubsystemsGeneral OT
SectorsMultiple

What to Know

A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the local system. An unauthenticated attacker on an adjacent network can connect to the exposed service to push tampered container images, delete cached images, or access mirrored content. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-96577
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-96577