{"id":"CVE-2026-71460","published":"2026-09-23T19:19:02.410","lastModified":"2026-09-24T07:16:32.527","description":"/api/v2/config/ is protected only by IsAuthenticated.\n              license_info (account_number, subscription_id, pool_id,\n              sku, support_level, instance counts) returned to any\n              authenticated user. The superuser/auditor gate only covers\n              project_base_dir/project_local_paths/custom_virtualenvs,\n              not license_info. Enables social engineering against\n              Red Hat support and estate sizing reconnaissance.","cvssScore":4.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:71113","tags":[]},{"url":"https://access.redhat.com/errata/RHSA-2026:71114","tags":[]},{"url":"https://access.redhat.com/errata/RHSA-2026:71177","tags":[]},{"url":"https://access.redhat.com/errata/RHSA-2026:71179","tags":[]},{"url":"https://access.redhat.com/security/cve/CVE-2026-71460","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2512369","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}