Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-84828— Pcs: pcs: non-root haclient users can read arbitrary files via pcs host auth --token

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 PCS(Pacemaker 配置系统)中发现一个缺陷。属于 'haclient' 组的本地攻击者可以利用 'pcs host auth --token' 命令读取文件系统中任意文件的内容,前提是文件大小小于 256 字节。文件内容以 root 权限由 pcsd 守护进程读取,并可通过后续的集群节点间通信被攻击者窃取出。这可能导致敏感数据(如 API 密钥、令牌或配置密钥等)泄露,这些数据原本对攻击者而言是无法访问的。

CVSS 6.5 · Medium

Possible ATT&CK Techniques 2 AI

T1005 · Data from Local System T1042
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-84828

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Pcs: pcs: non-root haclient users can read arbitrary files via pcs host auth --token
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the files are shorter than 256 bytes. The file contents are read with root privileges by the pcsd daemon and can be exfiltrated by the attacker through subsequent cluster node communication. This allows disclosure of sensitive data such as API keys, tokens, or configuration secrets that would otherwise be inaccessible to the attacker.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
关键资源的不正确权限授予
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenStack Platform 16.2 - cpe:/a:redhat:openstack:16.2
Red Hat Red Hat OpenStack Platform 17.1 - cpe:/a:redhat:openstack:17.1

II. Public POCs for CVE-2026-84828

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-84828

登录查看更多情报信息。

Vendor Advisories for CVE-2026-84828 (1)

Other References for CVE-2026-84828 (1)

Same Patch Batch · Red Hat · 2026-09-10 · 8 CVEs total

CVE-2026-84042 7.8 HIGH Crun: crun: rootful krun with passt executes container payload as host root
CVE-2026-88924 7.0 HIGH Gvfs: gvfs-admin socket ownership race permits local root
CVE-2026-88770 6.5 MEDIUM Keycloak-services: keycloak-services: device authorization grant issues tokens to brute-fo
CVE-2026-88859 6.3 MEDIUM Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-
CVE-2026-88763 5.9 MEDIUM Skupper-router: skupper-router: unbounded recursion in amqp field parser leads to denial o
CVE-2026-88265 5.6 MEDIUM Crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mount write and
CVE-2026-88264 5.6 MEDIUM Crun: crun: /dev/console symlink follow allows root-owned file creation outside the rootfs

IV. Related Vulnerabilities

V. Comments for CVE-2026-84828

No comments yet


Leave a comment