A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the ServiceAccount token authorizes read access to every Secret in the cluster. The operator also bypasses the cache via direct API calls. Compromise of the operator pod would yield read access to every Secret in the cluster, including bootstrap tokens, cloud credentials, and other operators' secrets.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 08 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat build Of Apache Camel - Hawtio
|
|
| Vendors & Products |
Redhat build Of Apache Camel - Hawtio
|
Tue, 08 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the ServiceAccount token authorizes read access to every Secret in the cluster. The operator also bypasses the cache via direct API calls. Compromise of the operator pod would yield read access to every Secret in the cluster, including bootstrap tokens, cloud credentials, and other operators' secrets. | |
| Title | Hawtio-operator: hawtio-operator: cluster-wide secrets read/write granted to operator serviceaccount | |
| First Time appeared |
Redhat
Redhat apache Camel Hawtio |
|
| Weaknesses | CWE-269 | |
| CPEs | cpe:/a:redhat:apache_camel_hawtio:4 | |
| Vendors & Products |
Redhat
Redhat apache Camel Hawtio |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2026-09-08T11:27:49.823Z
Updated: 2026-09-08T14:05:23.465Z
Reserved: 2026-08-27T10:25:52.077Z
Link: CVE-2026-77968
Updated: 2026-09-08T14:05:13.749Z
Status : Awaiting Analysis
Published: 2026-09-08T12:16:59.427
Modified: 2026-09-08T19:08:15.590
Link: CVE-2026-77968