VulnerabilityAnalyzed
CVE-2026-10609
A missing authorization flaw was found in the OpenShift Cluster Logging Operator.
MEDIUM 6.8EPSS 0.38%
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying that the ClusterLogForwarder creator has permission to use those credentials, allowing a delegated editor to exfiltrate SA tokens and escalate privileges.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- redhat/cluster logging operator · redhat/logging subsystem for red hat openshift
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/CVE-2026-10609Mitigation, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2483943Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.