CVE-2026-78234
Awaiting Analysis Awaiting Analysis - Queue

Service CA Certificate Impersonation in Hawtio Operator

Vulnerability report for CVE-2026-78234, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: redhat-SADP

Description

A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource. Because the operator ships a ClusterRole that aggregates Hawtio CR permissions into the edit and admin roles, any user with edit access in any namespace can obtain a Service-CA-signed certificate with an arbitrary subject. This certificate can be used to impersonate any in-cluster service identity to peers that trust the Service CA for client authentication, including Jolokia agents and other Service-CA-trusting components.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat hawtio-operator *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in hawtio-operator allows users with edit access in any namespace to obtain a Service-CA-signed certificate with an arbitrary subject. The operator reads the OpenShift Service CA private signing key and uses it to mint client certificates, which can then be used to impersonate any in-cluster service identity to peers trusting the Service CA for client authentication.

Impact Analysis

An attacker with edit access could impersonate services like Jolokia agents or other Service-CA-trusting components, potentially gaining unauthorized access to sensitive data or performing actions on behalf of those services. This could lead to data breaches, service disruption, or further lateral movement within the cluster.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection principles or HIPAA's security requirements. Organizations may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Remove or restrict the ClusterRole that aggregates Hawtio CR permissions into edit and admin roles to prevent unauthorized access to the Service CA private signing key.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78234. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart