CVE-2026-1531
8.1Red Hat · Red Hat Satellite
Red Hat Satellite fails to validate SSL certificates when connecting to OpenShift if no CA is specified, enabling Man-in-the-Middle attacks.
Executive summary
A high-severity flaw in Red Hat Satellite allows remote attackers to perform Man-in-the-Middle attacks by exploiting improper SSL certificate validation during OpenShift configuration.
Vulnerability
This vulnerability involves improper certificate validation (CWE-295) where the system disables SSL verification if a Certificate Authority is not explicitly configured. The attack requires low privileges and can be triggered by a remote attacker capable of intercepting network traffic.
Business impact
The vulnerability poses a significant risk to data integrity and confidentiality. By performing a Man-in-the-Middle attack, an adversary can intercept, view, or alter sensitive communications between Red Hat Satellite and OpenShift clusters. With a CVSS score of 8.1, this flaw is classified as High, reflecting the potential for total impact on data confidentiality and integrity within the managed environment.
Remediation
Immediate Action: Update Red Hat Satellite components to the fixed versions specified in the Red Hat security advisories (RHSA-2026:5968, RHSA-2026:5970, and RHSA-2026:5971).
Proactive Monitoring: Review system logs for unusual network connection errors or certificate-related warnings that may indicate intercepted traffic attempts.
Compensating Controls: Ensure that all connections between Satellite and OpenShift are explicitly configured with valid Certificate Authority certificates to enforce SSL validation until patches can be applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the potential for unauthorized data access or modification, organizations should prioritize the deployment of the provided Red Hat errata. Applying the updates is essential to ensuring proper certificate validation and securing the communication channel between Satellite and OpenShift infrastructure.
More Red Hat CVEs all →
History
- Disclosed CVE record published
- Published in the daily brief high section
- Published in the daily brief high section
- Analyst report written
Sources
Originally found and disclosed by This issue was discovered by Evgeni Golov (Red Hat)., per the CVE Program record.
- RHSA-2026:5968 Vendor advisory
- RHSA-2026:5970 Vendor advisory
- RHSA-2026:5971 Vendor advisory
- Vulnerability database entry
- RHBZ#2433786 Issue tracker