PT-2026-87035 · Red Hat · Red Hat Build Of Apache Camel - Hawtio 4

CVE-2026-78234

·

Published

2026-09-08

·

Updated

2026-09-09

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
If a namespaced CR can mint cluster identity, that operator is a CA.
If a namespaced CR can mint cluster identity, that operator is a CA. CVE-2026-78234, hawtio-operator. it reads the OpenShift Service CA private key, then issues a client cert with whatever CN you put on the Hawtio CR. the operator aggregates that permission into edit/admin.
so “I can edit one namespace” becomes “I can impersonate any service that trusts Service CA,” Jolokia included.
Red Hat scored it Important because you need edit. edit is not a high bar in most clusters.
stop giving controllers the Service CA key because the UI wanted pretty certs. CSR API or a private signer. anything else is cluster-admin with extra steps.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78234

Affected Products

Red Hat Build Of Apache Camel - Hawtio 4