Bug 2524894 (CVE-2026-78234) - CVE-2026-78234 hawtio-operator: hawtio-operator: Service-CA signing oracle allows arbitrary-CN certificate issuance to namespace edit users
Summary: CVE-2026-78234 hawtio-operator: hawtio-operator: Service-CA signing oracle al...
Keywords:
Status: NEW
Alias: CVE-2026-78234
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-27 09:53 UTC by OSIDB Bzimport
Modified: 2026-09-08 13:16 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-27 09:53:44 UTC
C-1 from Project Glasswing security audit of hawtio-operator. The operator reads the OpenShift Service CA private signing key and mints client certificates with a Subject CN supplied by the unprivileged author of the namespaced Hawtio CR. Any principal holding the edit or admin aggregated role in any namespace can obtain a Service-CA-signed certificate with an arbitrary subject, enabling impersonation of any in-cluster service identity. Source: hawtio-operator-security-audit.json#C-1.


Note You need to log in before you can comment on or make changes to this bug.