PT-2026-87035 · Red Hat · Red Hat Build Of Apache Camel - Hawtio 4
CVE-2026-78234
·
Published
2026-09-08
·
Updated
2026-09-09
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
If a namespaced CR can mint cluster identity, that operator is a CA.
If a namespaced CR can mint cluster identity, that operator is a CA. CVE-2026-78234, hawtio-operator. it reads the OpenShift Service CA private key, then issues a client cert with whatever CN you put on the Hawtio CR. the operator aggregates that permission into edit/admin.
so “I can edit one namespace” becomes “I can impersonate any service that trusts Service CA,” Jolokia included.
Red Hat scored it Important because you need edit. edit is not a high bar in most clusters.
stop giving controllers the Service CA key because the UI wanted pretty certs. CSR API or a private signer. anything else is cluster-admin with extra steps.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Build Of Apache Camel - Hawtio 4