Skip to content
Red HatCVE-2026-84828

Red Hat Enterprise Linux 10: insecure permissions

Medium6.5CVE-2026-84828 · Published Sep 10, 2026 · updated Sep 14, 2026

A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the files are shorter than 256 bytes. The file contents are read with root privileges by the pcsd daemon and can be exfiltrated by the attacker through subsequent cluster node communication. This allows disclosure of sensitive data such as API keys, tokens, or configuration secrets that would otherwise be inaccessible to the attacker.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Red Hat OpenShift Container Platform 4
Product
all versionsNo fix yet
Red Hat OpenStack Platform 16.2
Product
all versionsNo fix yet
Red Hat OpenStack Platform 17.1
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat admin backend of gvfs: race condition
High7.0Sep 10
A flaw was found in Evolution
Medium6.3Sep 10
Red Hat crun.: improper privilege management
High7.8Sep 10
Red Hat crun.: link following
Medium5.6Sep 10
Red Hat crun. After pivot_root: link following
Medium5.6Sep 10
Red Hat Service Interconnect 2: denial of service
Medium5.9Sep 10

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.