{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-78234","assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","state":"PUBLISHED","assignerShortName":"redhat","dateReserved":"2026-08-27T10:25:52.070Z","datePublished":"2026-09-08T11:27:52.787Z","dateUpdated":"2026-09-08T17:14:44.894Z"},"containers":{"cna":{"title":"Hawtio-operator: hawtio-operator: service-ca signing oracle allows arbitrary-cn certificate issuance to namespace edit users","metrics":[{"other":{"content":{"value":"Important","namespace":"https://access.redhat.com/security/updates/classification/"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"format":"CVSS"}],"descriptions":[{"lang":"en","value":"A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource. Because the operator ships a ClusterRole that aggregates Hawtio CR permissions into the edit and admin roles, any user with edit access in any namespace can obtain a Service-CA-signed certificate with an arbitrary subject. This certificate can be used to impersonate any in-cluster service identity to peers that trust the Service CA for client authentication, including Jolokia agents and other Service-CA-trusting components."}],"affected":[{"vendor":"Red Hat","product":"Red Hat build of Apache Camel - HawtIO 4","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhbac-4/hawtio-gateway-rhel9","defaultStatus":"affected","cpes":["cpe:/a:redhat:apache_camel_hawtio:4"]},{"vendor":"Red Hat","product":"Red Hat build of Apache Camel - HawtIO 4","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhbac-4/hawtio-operator-bundle","defaultStatus":"affected","cpes":["cpe:/a:redhat:apache_camel_hawtio:4"]},{"vendor":"Red Hat","product":"Red Hat build of Apache Camel - HawtIO 4","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhbac-4/hawtio-rhel9","defaultStatus":"affected","cpes":["cpe:/a:redhat:apache_camel_hawtio:4"]}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-78234","tags":["vdb-entry","x_refsource_REDHAT"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2524894","name":"RHBZ#2524894","tags":["issue-tracking","x_refsource_REDHAT"]}],"datePublic":"2026-09-08T10:55:10.366Z","problemTypes":[{"descriptions":[{"cweId":"CWE-295","description":"Improper Certificate Validation","lang":"en","type":"CWE"}]}],"x_redhatCweChain":"CWE-295: Improper Certificate Validation","workarounds":[{"lang":"en","value":"Do not set spec.routeHostName to values outside the operator's own namespace service names. Restrict which users can create or modify Hawtio custom resources via RBAC. Audit existing Hawtio CR instances for unexpected routeHostName values and rotate any TLS certificates that may have been issued with incorrect Common Names."}],"timeline":[{"lang":"en","time":"2026-05-20T00:00:00.000Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-09-08T10:55:10.366Z","value":"Made public."}],"providerMetadata":{"orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat","dateUpdated":"2026-09-08T17:14:44.894Z"},"x_generator":{"engine":"cvelib 1.8.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-08T12:18:30.594248Z","id":"CVE-2026-78234","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-08T12:19:06.844Z"}}]}}