Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-77968

Опубликовано: 08 сент. 2026
Источник: redhat
CVSS3: 8.2

Описание

A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the ServiceAccount token authorizes read access to every Secret in the cluster. The operator also bypasses the cache via direct API calls. Compromise of the operator pod would yield read access to every Secret in the cluster, including bootstrap tokens, cloud credentials, and other operators' secrets.

Отчет

Red Hat has determined that this vulnerability is Important severity. The hawtio-operator ServiceAccount has cluster-wide secrets read/write permissions that far exceed its operational needs. While exploitation requires prior compromise of the operator pod, the blast radius is the entire cluster's Secret corpus. Red Hat recommends scoping permissions to namespaced Roles created on demand for each Hawtio instance, with resourceNames restrictions for the Service CA secret.

Меры по смягчению последствий

Restrict access to the hawtio-operator namespace and limit who can exec into the operator pod. Monitor cluster audit logs for unexpected Secret access patterns from the hawtio-operator ServiceAccount. As a defence-in-depth measure, apply a NetworkPolicy to the operator namespace restricting egress to only the Kubernetes API server and required service endpoints.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel - HawtIO 4rhbac-4/hawtio-rhel9Affected
rhbac-4/hawtio-operator-bundleFixedRHSA-2026:6612009.09.2026
rhbac-4/hawtio-rhel9-operatorFixedRHSA-2026:6612009.09.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-269
https://bugzilla.redhat.com/show_bug.cgi?id=2524896hawtio-operator: hawtio-operator: Cluster-wide secrets read/write granted to operator ServiceAccount

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
nvd
9 дней назад

A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the ServiceAccount token authorizes read access to every Secret in the cluster. The operator also bypasses the cache via direct API calls. Compromise of the operator pod would yield read access to every Secret in the cluster, including bootstrap tokens, cloud credentials, and other operators' secrets.

CVSS3: 8.2
github
9 дней назад

A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the ServiceAccount token authorizes read access to every Secret in the cluster. The operator also bypasses the cache via direct API calls. Compromise of the operator pod would yield read access to every Secret in the cluster, including bootstrap tokens, cloud credentials, and other operators' secrets.

8.2 High

CVSS3