CVE-2026-0239: Chronosphere Chronocollector Information Disclosure Vulnerability (Severity: MEDIUM)
An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with network access to the collector service to retrieve sensitive information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in v0.116.0 - Upgrade
Upgrade
Chronosphere Chronocollectorto a version that resolves this vulnerability.Fixed in v0.116.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0239?
The severity of CVE-2026-0239 is classified as MEDIUM.
How do I fix CVE-2026-0239?
To fix CVE-2026-0239, it is recommended to apply the latest security updates and patches provided by Chronosphere.
Who is affected by CVE-2026-0239?
CVE-2026-0239 affects users of the Chronosphere Chronocollector with network access to the collector service.
What type of vulnerability is CVE-2026-0239?
CVE-2026-0239 is an information disclosure vulnerability.
Can an authenticated user be exploited through CVE-2026-0239?
No, CVE-2026-0239 can be exploited by unauthenticated attackers with network access.