Security Advisory

CVE-2026-55998

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-05 07:51:21
Last updated 2026-08-05 13:13:02
Assigner suse
CVSS score not scored
State PUBLISHED

Description

The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid cluster ID references a cluster that has private registry secrets configured, a nil pointer dereference in pkg/systemtemplate/private_registry.go causes the request to return HTTP 502 Bad Gateway. For cluster IDs that do not exist, the endpoint returns HTTP 200. This observable difference in response codes constitutes a reliable enumeration oracle.