{"id":"CVE-2026-93685","published":"2026-09-18T15:17:22.950","lastModified":"2026-09-21T21:17:19.317","description":"A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details, after completing a basic encrypted connection. This vulnerability does not enable direct remote code execution.","cvssScore":5.4,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","cwes":["CWE-200"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-93685","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2518377","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}