CVE-2026-10609
MEDIUMCVSS 6.8/10EPSS 0.24%
Last modified
This CVE is reserved or awaiting analysis. Details will appear once published by NVD.
Description
A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying that the ClusterLogForwarder creator has permission to use those credentials, allowing a delegated editor to exfiltrate SA tokens and escalate privileges.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Are you affected by CVE-2026-10609?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
