CVE-2026-92615
CVE-2026-92615 is a medium-severity vulnerability with a CVSS 3.x base score of 6.6. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-413.
Key facts
- Severity: Medium (CVSS 3.x base score 6.6)
- EPSS exploit prediction: 0% (4th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-413
- Published:
- Last modified:
Description
A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include InsecureSkipVerify, a custom CA bundle, or tenant-supplied mTLS client certificates) and installs it into go-git's process-global client.Protocols map via gitclient.InstallProtocol("https", ...). Because the worker renders devices for multiple organizations concurrently from a shared goroutine pool, whichever tenant's repository configuration is written last wins for all in-flight git.Clone calls. This race condition can cause one tenant's TLS settings, including InsecureSkipVerify or mTLS client credentials, to leak into another tenant's git operations.
Frequently asked questions
- What is CVE-2026-92615?
- A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include InsecureSkipVerify, a custom CA bundle, or tenant-supplied mTLS client certificates) and installs it into go-git's process-global client.Protocols map via gitclient.InstallProtocol("https", ...). Because the worker renders devices for multiple organizations concurrently from a shared goroutine pool, whichever tenant's repository configuration is written last wins for all in-flight git.Clone calls. This race condition can cause one tenant's TLS settings, including InsecureSkipVerify or mTLS client credentials, to leak into another tenant's git operations.
- How severe is CVE-2026-92615?
- CVE-2026-92615 has a CVSS 3.x base score of 6.6, rated medium severity. It is exploitable over network with high attack complexity, requires high privileges and no user interaction. Impact on confidentiality is high, integrity low, and availability none.
- Is CVE-2026-92615 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (4th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-92615?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-92615 published?
- CVE-2026-92615 was published on 2026-09-16 and last updated on 2026-09-17.
References
- https://access.redhat.com/security/cve/CVE-2026-92615
- https://bugzilla.redhat.com/show_bug.cgi?id=2518323
Other CWE-413 vulnerabilities
- CVE-2025-3450 — Critical (CVSS 10.0): An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and…
- CVE-2023-28649 — High (CVSS 8.6): The Hub in the Snap One OvrC cloud platform is a device used to centralize and manage nested devices connected to it. A…
- CVE-2019-8998 — High (CVSS 7.8): An information disclosure vulnerability leading to a potential local escalation of privilege in the procfs service (the…
- CVE-2022-49737 — High (CVSS 7.7): In X.Org X server 20.11 through 21.1.16, when a client application uses easystroke for mouse gestures, the main thread…
- CVE-2026-32748 — High (CVSS 7.5): Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected…
- CVE-2025-0003 — High (CVSS 7.3): Inadequate lock protection within Xilinx Run time may allow a local attacker to trigger a Use-After-Free condition…