CVE-2026-80219
A flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-scoped OAuthClient with automatic grant approval (GrantMethod: auto) and no client secret (public client). The redirect URIs are derived from the operator-created Route, whose hostname is tenant-controlled via the Hawtio CR spec.routeHostName field. A malicious tenant can register an arbitrary hostname as a valid OAuth redirect target and, because grants are auto-approved, obtain OpenShift access tokens of any cluster user who visits the crafted authorization URL without any consent prompt.
Published:Sep 8, 2026
Last Modified:Sep 8, 2026
EPS:Sep 8, 2026
EPSS Score:
CVSS Score:8.7
Affected Products
Vendor
Product
Action
Vendor
Redhat
Product
Apache Camel Hawtio
Redhat
Apache Camel Hawtio
Vendor
Redhat
Product
Build Of Apache Camel - Hawtio
Redhat
Build Of Apache Camel - Hawtio
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
