Description

A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set. This insecure default allows a remote attacker, capable of intercepting network traffic between Satellite and OpenShift, to perform a Man-in-the-Middle (MITM) attack. Such an attack could lead to the disclosure or alteration of sensitive information.

INFO

Published Date :

2026-02-02T05:47:09.570Z

Last Modified :

2026-03-26T23:00:06.609Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2026-1531 vulnerability.

Vendors Products
Redhat
  • Satellite
  • Satellite Capsule
  • Satellite Maintenance
  • Satellite Utils

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact