CVE-2026-1784: External Control of System or Configuration Setting in Red Hat Red Hat OpenShift Container Platform 4.13
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.
AI Analysis
Technical Summary
This advisory covers the release of Red Hat OpenShift Container Platform 4.21.19, which includes security fixes for several vulnerabilities including CVE-2026-1784. The platform is a Kubernetes application platform for on-premise or private cloud environments. The update addresses multiple bugs and security issues, with Red Hat rating the security impact as Important. The advisory provides updated container images and references RPM package updates in a separate errata. Users should upgrade their clusters following Red Hat's documented procedures to apply these fixes.
Potential Impact
The vulnerabilities addressed have a high impact potential, with the CVSS vector for CVE-2026-1784 indicating local attack vector, low attack complexity, low privileges required, no user interaction, scope changed, and high confidentiality, integrity, and availability impacts. This means exploitation could lead to significant compromise of the platform's security. However, there are no known exploits in the wild at the time of this advisory.
Mitigation Recommendations
Red Hat has released updated container images and RPM packages for OpenShift Container Platform 4.21.19 that include fixes for these vulnerabilities. Users should upgrade to these updated versions as soon as they are available in their release channels. Detailed upgrade instructions are provided by Red Hat in their official documentation. No alternative mitigations or workarounds are specified, so applying the official update is the recommended remediation.
CVE-2026-1784: External Control of System or Configuration Setting in Red Hat Red Hat OpenShift Container Platform 4.13
Description
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.
CVSS v3.1
Score 8.8high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory covers the release of Red Hat OpenShift Container Platform 4.21.19, which includes security fixes for several vulnerabilities including CVE-2026-1784. The platform is a Kubernetes application platform for on-premise or private cloud environments. The update addresses multiple bugs and security issues, with Red Hat rating the security impact as Important. The advisory provides updated container images and references RPM package updates in a separate errata. Users should upgrade their clusters following Red Hat's documented procedures to apply these fixes.
Potential Impact
The vulnerabilities addressed have a high impact potential, with the CVSS vector for CVE-2026-1784 indicating local attack vector, low attack complexity, low privileges required, no user interaction, scope changed, and high confidentiality, integrity, and availability impacts. This means exploitation could lead to significant compromise of the platform's security. However, there are no known exploits in the wild at the time of this advisory.
Mitigation Recommendations
Red Hat has released updated container images and RPM packages for OpenShift Container Platform 4.21.19 that include fixes for these vulnerabilities. Users should upgrade to these updated versions as soon as they are available in their release channels. Detailed upgrade instructions are provided by Red Hat in their official documentation. No alternative mitigations or workarounds are specified, so applying the official update is the recommended remediation.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:23241
- Cve Count
- 3
- Additional Cves
- ["CVE-2026-33186","CVE-2026-34986"]
- Cvss Version
- null
Threat ID: 6a2abb30815e7002b8ea1970
Added to database: 06/11/2026, 13:42:08 UTC
Last enriched: 07/26/2026, 01:39:59 UTC
Last updated: 07/31/2026, 22:28:32 UTC
Views: 135
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.