#VU119997 Configuration in Lightspeed (formerly Insights) for Runtimes - CVE-2025-11393

 

#VU119997 Configuration in Lightspeed (formerly Insights) for Runtimes - CVE-2025-11393

Published: December 16, 2025


Vulnerability identifier: #VU119997
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2025-11393
CWE-ID: CWE-16
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Lightspeed (formerly Insights) for Runtimes
Software vendor:
Red Hat Inc.

Description

The issue may allow a remote user to compromise the affected cluster.

The issue exists due to incorrect configuration of the internal proxy component in runtimes-inventory-rhel8-operator. The proxy attaches the cluster's main administrative credentials to any command it receives, instead of only the specific reports it is supposed to handle. This allows a standard user within the cluster to send unauthorized commands to the management platform, effectively acting with the full permissions of the cluster administrator.


Remediation

Install updates from vendor's website.

External links