A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set. This insecure default allows a remote attacker, capable of intercepting network traffic between Satellite and OpenShift, to perform a Man-in-the-Middle (MITM) attack. Such an attack could lead to the disclosure or alteration of sensitive information.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

To mitigate this issue, ensure that a Certificate Authority (CA) certificate is explicitly configured when setting up the connection to OpenShift in foreman_kubevirt. This will enable SSL verification and prevent Man-in-the-Middle attacks. Refer to the foreman_kubevirt documentation for specific instructions on configuring CA certificates. A restart or service reload may be required for the changes to take effect.

History

Mon, 02 Feb 2026 06:00:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set. This insecure default allows a remote attacker, capable of intercepting network traffic between Satellite and OpenShift, to perform a Man-in-the-Middle (MITM) attack. Such an attack could lead to the disclosure or alteration of sensitive information.
Title foreman-kubevirt: foreman_kubevirt: Man-in-the-Middle due to insecure default SSL verification Foreman-kubevirt: foreman_kubevirt: man-in-the-middle due to insecure default ssl verification
First Time appeared Redhat
Redhat satellite
CPEs cpe:/a:redhat:satellite:6
Vendors & Products Redhat
Redhat satellite
References

Thu, 29 Jan 2026 00:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title foreman-kubevirt: foreman_kubevirt: Man-in-the-Middle due to insecure default SSL verification
Weaknesses CWE-295
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

threat_severity

Important


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-02-02T05:47:09.570Z

Reserved: 2026-01-28T12:52:40.355Z

Link: CVE-2026-1531

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-02T06:16:20.790

Modified: 2026-02-02T06:16:20.790

Link: CVE-2026-1531

cve-icon Redhat

Severity : Important

Publid Date: 2026-01-28T12:34:00Z

Links: CVE-2026-1531 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses