CVE-2026-10609

A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying that the ClusterLogForwarder creator has permission to use those credentials, allowing a delegated editor to exfiltrate SA tokens and escalate privileges.
References
Link Resource
https://access.redhat.com/security/cve/CVE-2026-10609 Mitigation Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2483943 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:cluster_logging_operator:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:logging_subsystem_for_red_hat_openshift:-:*:*:*:*:*:*:*

History

08 Jul 2026, 15:10

Type Values Removed Values Added
CPE cpe:2.3:a:redhat:cluster_logging_operator:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:logging_subsystem_for_red_hat_openshift:-:*:*:*:*:*:*:*
References () https://access.redhat.com/security/cve/CVE-2026-10609 - () https://access.redhat.com/security/cve/CVE-2026-10609 - Mitigation, Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2483943 - () https://bugzilla.redhat.com/show_bug.cgi?id=2483943 - Issue Tracking, Vendor Advisory
First Time Redhat cluster Logging Operator
Redhat logging Subsystem For Red Hat Openshift
Redhat

23 Jun 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-23 14:17

Updated : 2026-07-08 15:10


NVD link : CVE-2026-10609

Mitre link : CVE-2026-10609

CVE.ORG link : CVE-2026-10609


JSON object : View

Products Affected

redhat

  • logging_subsystem_for_red_hat_openshift
  • cluster_logging_operator
CWE
CWE-862

Missing Authorization