Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in console. When the `HTTPS_PROXY` environment variable is not configured, the console component fails to verify Transport Layer Security (TLS) certificates for outbound connections. A network-positioned attacker (Man-in-the-Middle) can exploit this vulnerability to intercept the cluster pull-secret while it is being sent to console.redhat.com. This pull-secret is a critical credential that provides access to Red Hat container registries and cloud services, potentially leading to unauthorized access and sensitive information disclosure. | Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| Title | console: console: TLS verification disabled when sending hub pull-secret to console.redhat.com | Microsoft Office Word Information Disclosure Vulnerability |
| First Time appeared |
Microsoft
Microsoft 365 Apps Microsoft office 2019 Microsoft office 2021 Microsoft office 2024 Microsoft word 2016 |
|
| Weaknesses | CWE-125 CWE-193 |
|
| CPEs | cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:* cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:* cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:* cpe:2.3:a:microsoft:word_2016:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft 365 Apps Microsoft office 2019 Microsoft office 2021 Microsoft office 2024 Microsoft word 2016 |
|
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat console |
|
| Vendors & Products |
Redhat
Redhat console |
Tue, 11 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in console. When the `HTTPS_PROXY` environment variable is not configured, the console component fails to verify Transport Layer Security (TLS) certificates for outbound connections. A network-positioned attacker (Man-in-the-Middle) can exploit this vulnerability to intercept the cluster pull-secret while it is being sent to console.redhat.com. This pull-secret is a critical credential that provides access to Red Hat container registries and cloud services, potentially leading to unauthorized access and sensitive information disclosure. | |
| Title | console: console: TLS verification disabled when sending hub pull-secret to console.redhat.com | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-08-11T18:52:04.948Z
Reserved: 2026-07-27T19:02:26.601Z
Link: CVE-2026-66806
No data.
Status : Awaiting Analysis
Published: 2026-08-11T17:19:01.980
Modified: 2026-08-11T18:53:42.910
Link: CVE-2026-66806
OpenCVE Enrichment
Updated: 2026-08-11T14:19:31Z