CVE-2026-92747 PUBLISHED

Cockpit-machines: cockpit-machines: sensitive data exposure of guest credentials via json argument in process list

Assigner: redhat
Reserved: 16.09.2026 Published: 18.09.2026 Updated: 18.09.2026

A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as rootPassword and userPassword. This occurs when the install_machine.py script passes these credentials as a JSON command-line argument during VM creation or installation. The exposure is limited to the period when the installation workflow is active and depends on host process-visibility policies.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CVSS Score: 5

Product Status

Vendor Red Hat
Product Red Hat Enterprise Linux 10
Versions Default: affected
Vendor Red Hat
Product Red Hat Enterprise Linux 9
Versions Default: affected

Credits

  • This issue was discovered by Found by AISLE in partnership with Red Hat.

References

Problem Types

  • Invocation of Process Using Visible Sensitive Information CWE