Bug 2524896 (CVE-2026-77968)

Summary: CVE-2026-77968 hawtio-operator: hawtio-operator: Cluster-wide secrets read/write granted to operator ServiceAccount
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: abrianik, ggrzybek, jraez, parichar, security-response-team, tasato
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the ServiceAccount token authorizes read access to every Secret in the cluster. The operator also bypasses the cache via direct API calls. Compromise of the operator pod would yield read access to every Secret in the cluster, including bootstrap tokens, cloud credentials, and other operators' secrets.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-27 09:53:48 UTC
H-1 from Project Glasswing security audit of hawtio-operator. The ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. The controller-runtime label-selector cache is a memory optimisation only; the SA token authorises GET/LIST on every Secret. Compromise of the operator pod yields read of every Secret in the cluster. Source: hawtio-operator-security-audit.json#H-1.