CVE-2026-80219: Weak Authentication in Red Hat Red Hat build of Apache Camel - HawtIO 4
A flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-scoped OAuthClient with automatic grant approval (GrantMethod: auto) and no client secret (public client). The redirect URIs are derived from the operator-created Route, whose hostname is tenant-controlled via the Hawtio CR spec.routeHostName field. A malicious tenant can register an arbitrary hostname as a valid OAuth redirect target and, because grants are auto-approved, obtain OpenShift access tokens of any cluster user who visits the crafted authorization URL without any consent prompt.
AI Analysis
Technical Summary
The vulnerability in hawtio-operator occurs because it creates an OAuthClient with GrantMethod set to 'auto' and no client secret, making it a public client with automatic grant approval. The redirect URIs are derived from a Route whose hostname is controlled by the tenant via the Hawtio CR spec.routeHostName field. A malicious tenant with edit access in any namespace can register an arbitrary hostname as a redirect target and craft an authorization URL that steals OAuth tokens from any cluster user who visits it, bypassing user consent. This leads to unauthorized access tokens being issued, compromising confidentiality and integrity of user sessions in OpenShift clusters.
Potential Impact
An attacker with edit access in any namespace can steal OAuth tokens of any cluster user without their consent by exploiting the automatic grant approval and tenant-controlled redirect URIs. This allows the attacker to impersonate users and gain unauthorized access to cluster resources, resulting in high confidentiality and integrity impact. Availability is not affected.
Mitigation Recommendations
Red Hat recommends administrators manually patch the OAuthClient resource created by the hawtio-operator to set grantMethod to 'prompt' instead of 'auto' and add a client secret. This forces explicit user consent for each OAuth authorization request and prevents unauthorized token acquisition. Additionally, administrators should monitor OpenShift OAuth server audit logs for unexpected authorization grants to the hawtio OAuthClient. No official fix or patch version is currently confirmed; check the Red Hat advisory for updates.
CVE-2026-80219: Weak Authentication in Red Hat Red Hat build of Apache Camel - HawtIO 4
Description
A flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-scoped OAuthClient with automatic grant approval (GrantMethod: auto) and no client secret (public client). The redirect URIs are derived from the operator-created Route, whose hostname is tenant-controlled via the Hawtio CR spec.routeHostName field. A malicious tenant can register an arbitrary hostname as a valid OAuth redirect target and, because grants are auto-approved, obtain OpenShift access tokens of any cluster user who visits the crafted authorization URL without any consent prompt.
CVSS v3.1
Score 8.7high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in hawtio-operator occurs because it creates an OAuthClient with GrantMethod set to 'auto' and no client secret, making it a public client with automatic grant approval. The redirect URIs are derived from a Route whose hostname is controlled by the tenant via the Hawtio CR spec.routeHostName field. A malicious tenant with edit access in any namespace can register an arbitrary hostname as a redirect target and craft an authorization URL that steals OAuth tokens from any cluster user who visits it, bypassing user consent. This leads to unauthorized access tokens being issued, compromising confidentiality and integrity of user sessions in OpenShift clusters.
Potential Impact
An attacker with edit access in any namespace can steal OAuth tokens of any cluster user without their consent by exploiting the automatic grant approval and tenant-controlled redirect URIs. This allows the attacker to impersonate users and gain unauthorized access to cluster resources, resulting in high confidentiality and integrity impact. Availability is not affected.
Mitigation Recommendations
Red Hat recommends administrators manually patch the OAuthClient resource created by the hawtio-operator to set grantMethod to 'prompt' instead of 'auto' and add a client secret. This forces explicit user consent for each OAuth authorization request and prevents unauthorized token acquisition. Additionally, administrators should monitor OpenShift OAuth server audit logs for unexpected authorization grants to the hawtio OAuthClient. No official fix or patch version is currently confirmed; check the Red Hat advisory for updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-08-27T10:25:52.074Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-80219","vendor":"Red Hat"}]
Threat ID: 6a9ff395acd9273b49949e3e
Added to database: 09/08/2026, 11:37:57 UTC
Last enriched: 09/08/2026, 11:52:27 UTC
Last updated: 09/08/2026, 19:19:37 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.