Description
A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting network traffic from any IP address) without network payload encryption, the validation architecture implicitly trusts the link ID provided within incoming data packets. A remote, unauthenticated attacker can exploit this lack of validation by spoofing a legitimate link ID inside crafted network frames. This allows the attacker to fully bypass the ACL framework and inject arbitrary data packets into the application layer, potentially leading to data corruption or service instabilities.
Published: 2026-07-21
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the ACL subsystem of kronosnet versions up to 1.34. When the framework is configured to accept dynamic links from any IP address without encrypting the payload, it implicitly trusts the link identifier supplied in received packets. An attacker who can transmit custom network frames can spoof a legitimate link ID, bypass the ACL mechanism, and inject arbitrary data into the application layer. This bypass is a classic access‑control flaw (CWE-290) and can cause data corruption or service instability.

Affected Systems

Affected products include Red Hat Enterprise Linux 8, 9 and 10 as well as Red Hat OpenShift Container Platform 4, all of which may run kronosnet 1.34 or earlier.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity. The EPSS score of 0.00165 (approximately 0.17%) indicates a very low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. The likely attack vector is remote, over the network, and requires no authentication; it exploits a misconfiguration that allows unencrypted dynamic links. While the impact is confined to the application layer, successful exploitation could corrupt data or destabilize services. Organizations that still run the vulnerable kronosnet version with open dynamic links should evaluate the potential impact immediately.

Generated by OpenCVE AI on July 30, 2026 at 18:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade kronosnet to a version newer than 1.34.
  • In the kronosnet configuration, disable dynamic unencrypted links or enforce encryption for all network traffic.
  • Restrict dynamic link access to trusted IP ranges and apply strict ACL rules.

Generated by OpenCVE AI on July 30, 2026 at 18:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift Container Platform
Vendors & Products Redhat openshift Container Platform

Wed, 22 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title kronosnet: kronosnet: access control list bypass via link ID spoofing on unencrypted dynamic links Kronosnet: kronosnet: access control list bypass via link id spoofing on unencrypted dynamic links
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References

Mon, 20 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting network traffic from any IP address) without network payload encryption, the validation architecture implicitly trusts the link ID provided within incoming data packets. A remote, unauthenticated attacker can exploit this lack of validation by spoofing a legitimate link ID inside crafted network frames. This allows the attacker to fully bypass the ACL framework and inject arbitrary data packets into the application layer, potentially leading to data corruption or service instabilities.
Title kronosnet: kronosnet: access control list bypass via link ID spoofing on unencrypted dynamic links
Weaknesses CWE-290
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L'}

threat_severity

Low


Subscriptions

Redhat Enterprise Linux Openshift Openshift Container Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-22T14:20:07.617Z

Reserved: 2026-07-15T10:39:01.541Z

Link: CVE-2026-15812

cve-icon Vulnrichment

Updated: 2026-07-22T14:20:01.240Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Low

Publid Date: 2026-07-15T10:46:00Z

Links: CVE-2026-15812 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:22:37Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing