CVE-2026-19278

A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configures M2M role mappings, the system uses unanchored regular expressions for matching claim values. This allows an attacker with a valid OpenID Connect (OIDC) token, whose claim value is a superstring of a configured pattern, to gain unauthorized access to roles they were not intended to receive. This can lead to privilege escalation within the system.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-10 13:17

Updated : 2026-08-14 19:07


NVD link : CVE-2026-19278

Mitre link : CVE-2026-19278

CVE.ORG link : CVE-2026-19278


JSON object : View

Products Affected

No product.

CWE
CWE-625

Permissive Regular Expression