Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-77968: Improper Privilege Management in Red Hat Red Hat build of Apache Camel - HawtIO 4

0
High
VulnerabilityCVE-2026-77968cvecve-2026-77968
Published: 09/08/2026 (09/08/2026, 11:27:49 UTC)
Source: CVE Database V5
Vendor/Project: Red Hat
Product: Red Hat build of Apache Camel - HawtIO 4

Description

A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the ServiceAccount token authorizes read access to every Secret in the cluster. The operator also bypasses the cache via direct API calls. Compromise of the operator pod would yield read access to every Secret in the cluster, including bootstrap tokens, cloud credentials, and other operators' secrets.

CVSS v3.1

Score 8.2high

Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/08/2026, 11:52:53 UTC

Technical Analysis

The hawtio-operator's ClusterRole grants secrets permissions (create, get, list, update, watch) cluster-wide, exceeding operational needs. Although the operator uses a label-selector cache for optimization, its ServiceAccount token authorizes read access to all Secrets in the cluster, and it bypasses the cache via direct API calls. If an attacker compromises the operator pod, they gain read access to every Secret, including highly sensitive credentials. Red Hat classifies this as an Important severity issue with a CVSS 3.1 score of 8.2 (AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N). Red Hat advises restricting permissions to namespaced Roles with resourceName restrictions, limiting access to the operator namespace, monitoring audit logs for unusual Secret access, and applying NetworkPolicy restrictions. No official fix or patch is currently available according to the vendor advisory.

Potential Impact

Compromise of the hawtio-operator pod allows an attacker to read every Secret in the Kubernetes cluster, including bootstrap tokens, cloud credentials, and other operators' secrets. This can lead to significant confidentiality and integrity breaches across the cluster. The vulnerability requires prior pod compromise but has a cluster-wide blast radius due to excessive permissions granted to the operator's ServiceAccount.

Mitigation Recommendations

Red Hat recommends scoping permissions to namespaced Roles created on demand for each Hawtio instance, with resourceNames restrictions for the Service CA secret. Restrict access to the hawtio-operator namespace and limit who can exec into the operator pod. Monitor cluster audit logs for unexpected Secret access patterns from the hawtio-operator ServiceAccount. As a defense-in-depth measure, apply a NetworkPolicy to the operator namespace restricting egress to only the Kubernetes API server and required service endpoints. No official patch or fix is currently confirmed; check the vendor advisory for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
redhat
Date Reserved
2026-08-27T10:25:52.077Z
Cvss Version
3.1
State
PUBLISHED
Remediation Level
null
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-77968","vendor":"Red Hat"}]

Threat ID: 6a9ff394acd9273b49949e30

Added to database: 09/08/2026, 11:37:56 UTC

Last enriched: 09/08/2026, 11:52:53 UTC

Last updated: 09/09/2026, 01:19:44 UTC

Views: 16

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses