CVE-2026-10609

A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying that the ClusterLogForwarder creator has permission to use those credentials, allowing a delegated editor to exfiltrate SA tokens and escalate privileges.
References
Link Resource
https://access.redhat.com/security/cve/CVE-2026-10609 Mitigation Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2483943 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:cluster_logging_operator:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:logging_subsystem_for_red_hat_openshift:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-23 14:17

Updated : 2026-07-08 15:10


NVD link : CVE-2026-10609

Mitre link : CVE-2026-10609

CVE.ORG link : CVE-2026-10609


JSON object : View

Products Affected

redhat

  • cluster_logging_operator
  • logging_subsystem_for_red_hat_openshift
CWE
CWE-862

Missing Authorization