PT-2026-51518 · Red Hat · Openshift Cluster Logging Operator

·

CVE-2026-10609

·

Published

2026-06-23

·

Updated

2026-06-23

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenShift Cluster Logging Operator (affected versions not specified)
Description A missing authorization flaw exists in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying if the creator of the ClusterLogForwarder has the necessary permissions to use those credentials. This allows a delegated editor to exfiltrate ServiceAccount tokens and escalate privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10609

Affected Products

Openshift Cluster Logging Operator