{"id":"DEBIAN-CVE-2026-92745","details":"A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when it is passed as a command-line argument to a helper script during the token validation process. Successful exploitation could lead to the compromise of confidentiality, as the exposed token can be used to request access tokens.","modified":"2026-09-26T04:00:08.897281922Z","published":"2026-09-18T18:18:16.410Z","upstream":["CVE-2026-92745"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-92745"}],"affected":[{"package":{"name":"cockpit-machines","ecosystem":"Debian:12","purl":"pkg:deb/debian/cockpit-machines?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["288-1","292-1","293-1","294-1","295-1","295-1~bpo12+1","296-1","297-1","297-1~bpo12+1","298-1","298-1~bpo12+1","299-1","299-1~bpo12+1","300-1","300-1~bpo12+1","301-1","302-1","302-1~bpo12+1","303-1","303-1~bpo12+1","304-1","304-1~bpo12+1","305-1","305-1~bpo12+1","306-1","307-1","307-1~bpo12+1","309-1","309-1~bpo12+1","310-1","310-1~bpo12+1","312-1","313-1","313-2","313-3","314-1","314-2","314-2~bpo12+1","315-1","315-1~bpo12+1","316-1","317-1","317-1~bpo12+1","318-1","318-1~bpo12+1","319-1","319-1~bpo12+1","320-1","320-1~bpo12+1","321-1","322-1","323-1","323-1~bpo12+1","324-1","324-1~bpo12+1","325-1","325-2","326-1","327-1","327-1~bpo12+1","328-1","329-1","329-1~bpo12+1","330-1","331-1","332-1","332-1~bpo12+1","334-1","335-1","336-1","338-1","338-1~bpo13+1","339-1","339-1~bpo13+1","341-1","341-1~bpo13+1","343-1","343-1~bpo13+1","345-1","345-1~bpo13+1","346-1","346-1~bpo13+1","347-1","347-1~bpo13+1","348-1","348-1~bpo13+1","350-1","350-1~bpo13+1","351-1","351-1~bpo13+1","353-1","353-2","353-3","353-3~bpo13+1","355-1","355-1~bpo13+1","356-1","356-1~bpo13+1","357-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-92745.json"}},{"package":{"name":"cockpit-machines","ecosystem":"Debian:13","purl":"pkg:deb/debian/cockpit-machines?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["332-1","334-1","335-1","336-1","338-1","338-1~bpo13+1","339-1","339-1~bpo13+1","341-1","341-1~bpo13+1","343-1","343-1~bpo13+1","345-1","345-1~bpo13+1","346-1","346-1~bpo13+1","347-1","347-1~bpo13+1","348-1","348-1~bpo13+1","350-1","350-1~bpo13+1","351-1","351-1~bpo13+1","353-1","353-2","353-3","353-3~bpo13+1","355-1","355-1~bpo13+1","356-1","356-1~bpo13+1","357-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-92745.json"}},{"package":{"name":"cockpit-machines","ecosystem":"Debian:14","purl":"pkg:deb/debian/cockpit-machines?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"357-1"}]}],"versions":["332-1","334-1","335-1","336-1","338-1","338-1~bpo13+1","339-1","339-1~bpo13+1","341-1","341-1~bpo13+1","343-1","343-1~bpo13+1","345-1","345-1~bpo13+1","346-1","346-1~bpo13+1","347-1","347-1~bpo13+1","348-1","348-1~bpo13+1","350-1","350-1~bpo13+1","351-1","351-1~bpo13+1","353-1","353-2","353-3","353-3~bpo13+1","355-1","355-1~bpo13+1","356-1","356-1~bpo13+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-92745.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"}]}