Configuration in Lightspeed (formerly Insights) for Runtimes - CVE-2025-11393

 

Configuration in Lightspeed (formerly Insights) for Runtimes - CVE-2025-11393

Published: December 16, 2025


Vulnerability identifier: #VU119997
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-11393
CWE-ID: CWE-16
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The issue may allow a remote user to compromise the affected cluster.

The issue exists due to incorrect configuration of the internal proxy component in runtimes-inventory-rhel8-operator. The proxy attaches the cluster's main administrative credentials to any command it receives, instead of only the specific reports it is supposed to handle. This allows a standard user within the cluster to send unauthorized commands to the management platform, effectively acting with the full permissions of the cluster administrator.


Affected software

Lightspeed (formerly Insights) for Runtimes

How to mitigate CVE-2025-11393

Install updates from vendor's website.

Lightspeed (formerly Insights) for Runtimes - update to 1.0.0

External References

Related Security Bulletins