CVE-2026-10609: fallo de gravedad media en Red Hat Logging Subsystem for Red Hat OpenShift
Openshift/cluster-logging-operator: cluster logging operator creates and forwards serviceaccount tokens without verifying clf creator authorization
Publicada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.8epss 0.4%
probabilidad de explotación
0.4%top 71% de las CVE
explotación observada
noninguna fuente lo reporta
A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying that the ClusterLogForwarder creator has permission to use those credentials, allowing a delegated editor to exfiltrate SA tokens and escalate privileges.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Productos afectados
Red Hat · Logging Subsystem for Red Hat OpenShiftCVEs relacionadas — Red Hat Logging Subsystem for Red Hat OpenShift
En el mismo producto, de las más peligrosas a las menos.
CVE-2024-11831MEDIUMNpm-serialize-javascript: cross-site scripting (xss) in serialize-javascriptEPSS 1.1%CVE-2026-16242CRITICALHypershift: konnectivity proxy-server accepts agent connections without validating client certificatesEPSS 0.9%CVE-2024-5037HIGHOpenshift/telemeter: iss check during jwt authentication can be bypassedEPSS 0.8%CVE-2024-0874MEDIUMCoredns: cd bit response is cached and served laterEPSS 0.8%CVE-2026-0810HIGHGix-date: gix-date: undefined behavior due to invalid string generationEPSS 0.2%