PT-2026-87035 · Red Hat · Red Hat Build Of Apache Camel - Hawtio 4
CVE-2026-78234
·
Publicado
2026-09-08
·
Atualizado
2026-09-09
CVSS v3.1
9.9
Crítica
| Vetor | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
If a namespaced CR can mint cluster identity, that operator is a CA.
If a namespaced CR can mint cluster identity, that operator is a CA. CVE-2026-78234, hawtio-operator. it reads the OpenShift Service CA private key, then issues a client cert with whatever CN you put on the Hawtio CR. the operator aggregates that permission into edit/admin.
so “I can edit one namespace” becomes “I can impersonate any service that trusts Service CA,” Jolokia included.
Red Hat scored it Important because you need edit. edit is not a high bar in most clusters.
stop giving controllers the Service CA key because the UI wanted pretty certs. CSR API or a private signer. anything else is cluster-admin with extra steps.
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat Build Of Apache Camel - Hawtio 4