Bug 2476266 (CVE-2026-92745) - CVE-2026-92745 cockpit-machines: cockpit-machines: Information Disclosure of RHSM Offline Token via Process Arguments
Summary: CVE-2026-92745 cockpit-machines: cockpit-machines: Information Disclosure of ...
Keywords:
Status: NEW
Alias: CVE-2026-92745
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2537074
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-11 22:22 UTC by OSIDB Bzimport
Modified: 2026-09-18 19:19 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-05-11 22:22:48 UTC
AI_ONLY_REPORT
package: cockpit-machines-348-1.el10
------
Summary: RHSM Offline Token Exposure via Process Arguments in  
`getAccessToken()` (CWE-214): the package passes the RHSM offline token to  
a helper via argv, allowing local disclosure through process metadata while  
token validation is running.
Requirements to exploit: An attacker needs local access to the host running  
Cockpit Machines, the ability to inspect another user's process metadata  
while the RHSM token-validation flow is active, and a deployment without  
`/proc` visibility restrictions that would otherwise block command-line  
inspection.
Component affected: `cockpit-machines`; `src/libvirtApi/rhel-images.ts`  
`getAccessToken()`; `src/scripts/rhsm/get_access_token.py`
Version affected: `cockpit-machines-348-1.el10`
Patch available: no released package fix established; proposed patch  
included below
Version fixed: unknown
Upstream coordination: Not notified.
CVSS: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N - 4.7 (MEDIUM)
AV:L - Exploitation requires local access to the host where Cockpit  
Machines is running.
AC:L - On systems without restrictive `/proc` settings, observing helper  
command lines is straightforward once the process starts.
PR:L - A low-privileged local account is sufficient to inspect process  
metadata in affected configurations.
UI:R - A user must trigger the RHSM offline-token validation flow so the  
helper process is spawned with the secret in argv.
S:U - The impact stays within the same security scope.
C:H - The exposed value is a sensitive RHSM offline token that can be  
used to request access tokens.
I:N - This issue does not directly alter data or system state.
A:N - This issue does not directly reduce service availability.
Impact: Moderate. This issue can expose a high-value credential and  
therefore compromise confidentiality, but exploitation is local,  
timing-sensitive, and dependent on process-visibility configuration. Under  
Red Hat's severity guidance, that fits a confidentiality compromise that is  
real but less easily exploited than an Important issue.
Embargo: no
Reason: This is a local information disclosure issue with  
configuration-dependent exploitability and a straightforward remediation  
path. It does not present the kind of remotely exploitable or rapidly  
weaponizable condition that typically warrants embargo.
Acknowledgement: Aisle Research
Vulnerability Details: The RHSM offline token is serialized into JSON and  
passed to a Python helper as a command-line argument. The helper then reads  
the secret from `sys.argv[1]` and uses it as the `refresh_token` parameter  
when requesting an access token:
```ts
export function getAccessToken(offlineToken: string): cockpit.Spawn<string>  
{
logDebug(`Get access token`);
const arg = JSON.stringify({ offlineToken });
return python.spawn(getAccessTokenScript, [arg], { err: "message",  
environ: ['LC_ALL=C.UTF-8'] });
}
```
```py
args = json.loads(sys.argv[1], strict=False)
data = {
"grant_type": "refresh_token",
"client_id": "rhsm-api",
"refresh_token": args["offlineToken"]
}
```
Because the secret is present in argv, it can be exposed through process  
metadata such as `ps`, `pgrep -af`, or `/proc/<pid>/cmdline` while the  
helper is running. Reachability from the UI is direct through the Create VM  
RHEL download/token-validation flow. This is a local disclosure issue  
rather than a remote compromise; its practical exploitability depends on  
whether another local user can inspect that process metadata on the host.
Steps to reproduce:
1. Start Cockpit Machines and open the Create VM flow.
2. Select `Download an OS` and choose a RHEL entry that requires an RHSM  
offline token.
3. Paste a valid or invalid offline token so the validation flow calls  
`getAccessToken()`.
4. From a second local shell on the same host, monitor the helper command  
line:
```bash
while true; do pgrep -af get_access_token.py; sleep 0.1; done
```
5. Observe that the helper process command line contains JSON with the  
`offlineToken` value.
If the host enforces restrictive `/proc` visibility settings such as  
`hidepid`, cross-user observation may be blocked. That limits  
exploitability, but it does not change the underlying secret-on-argv  
behavior.
Mitigation: Until a fixed build is available, avoid validating RHSM offline  
tokens through this flow on shared systems where untrusted local users can  
inspect process metadata. Restrict `/proc` visibility so unprivileged users  
cannot view other users' command lines.
Proposed Fix: Do not pass the offline token in argv. Spawn the helper  
without secret-bearing arguments and send the JSON payload over stdin  
instead.
```diff
diff --git a/src/libvirtApi/rhel-images.ts b/src/libvirtApi/rhel-images.ts
@@
export function getAccessToken(offlineToken: string):  
cockpit.Spawn<string> {
logDebug(`Get access token`);
   const arg = JSON.stringify({ offlineToken });

   return python.spawn(getAccessTokenScript, [arg], { err: "message",  
environ: ['LC_ALL=C.UTF-8'] });
+    const proc = python.spawn(getAccessTokenScript, [], { err: "message",  
environ: ['LC_ALL=C.UTF-8'] });
+    proc.input(JSON.stringify({ offlineToken }));
+    return proc;
  }
diff --git a/src/scripts/rhsm/get_access_token.py  
b/src/scripts/rhsm/get_access_token.py
@@
-args = json.loads(sys.argv[1], strict=False)
+args = json.loads(sys.stdin.read(), strict=False)
```


------
This report was generated using AI technology. Always review AI-generated  
content prior to use


Note You need to log in before you can comment on or make changes to this bug.