Description
A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the local system. An unauthenticated attacker on an adjacent network can connect to the exposed service to push tampered container images, delete cached images, or access mirrored content.
Published: 2026-10-01
Score: 7.1 High
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

Red Hat has not identified any known mitigations for this issue. Customers are advised to apply the available security update when released.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the local system. An unauthenticated attacker on an adjacent network can connect to the exposed service to push tampered container images, delete cached images, or access mirrored content.
Title oc-mirror__release-4.21: Embedded local cache registry listens on all interfaces without authentication, with delete enabled Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without authentication, with delete enabled
First Time appeared Redhat
Redhat assisted Installer
Redhat openshift
CPEs cpe:/a:redhat:assisted_installer:2
cpe:/a:redhat:openshift:4
Vendors & Products Redhat
Redhat assisted Installer
Redhat openshift
References

Thu, 24 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title oc-mirror__release-4.21: Embedded local cache registry listens on all interfaces without authentication, with delete enabled
Weaknesses CWE-306
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}

threat_severity

Important


Subscriptions

Redhat Assisted Installer Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-01T10:00:05.481Z

Reserved: 2026-09-23T13:30:40.232Z

Link: CVE-2026-96577

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T10:17:17.760

Modified: 2026-10-01T12:41:25.413

Link: CVE-2026-96577

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-23T14:05:25Z

Links: CVE-2026-96577 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T11:30:05Z

Weaknesses