Description
A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into the Route spec without validation or authorization checks. A namespace edit user, who normally cannot set custom Route hostnames, can use the operator as a confused deputy to claim arbitrary externally-routable hostnames, enabling subdomain takeover and, in combination with the auto-grant OAuthClient, OAuth redirect hijack.
Published: 2026-09-15
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary hostname claim enabling subdomain takeover and OAuth redirect hijack
Action: Apply Patch
AI Analysis

Impact

The Hawtio operator writes the tenant-supplied spec.routeHostName value directly into the Kubernetes Route specification without performing validation or authorization checks. A user who can edit namespace resources—who normally cannot set custom Route hostnames—can use the operator as a confused deputy to claim any externally routable hostname. This allows the attacker to take over subdomains and, in combination with the auto-grant OAuthClient, hijack OAuth redirect flows. The weakness is a classic lack of input validation and authorization, identified as CWE‑441.

Affected Systems

The affected product is the Red Hat build of Apache Camel – HawtIO 4, with the identified vulnerability present in the 4.x release line. No further granularity on sub‑versions is provided.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate severity vulnerability, while an EPSS score of fewer than 1 % suggests that exploitation is unlikely in the wild at present. The CVE is not listed in the CISA KEV catalog. Exploitability requires the attacker to possess namespace‑edit rights and to manipulate Hawtio custom resources, which can be achieved through an existing user account with those permissions. The operator’s cluster‑wide routes/custom‑host:create permission and the absence of hostname validation create a clear attack path for hostname hijacking. Administrators are recommended to assess whether the necessary permissions are properly scoped and to apply mitigations promptly.

Generated by OpenCVE AI on September 17, 2026 at 18:17 UTC.

Remediation

Vendor Workaround

Administrators can mitigate this issue by restricting which users can create or modify Hawtio custom resources using RBAC policies. Additionally, OpenShift admins can configure the router to use route admission policies that reject Routes claiming hostnames outside of allowed domain patterns. Review existing Hawtio CR instances for unexpected routeHostName values.


OpenCVE Recommended Actions

  • Upgrade to the latest Red Hat HawtIO 4 release that contains the operator fix
  • Restrict RBAC sotio custom resources
  • Configure Routes claiming hostnames outside of allowed domain patterns
  • Review existing Hawtio custom resources for unexpected routeHostName values

Generated by OpenCVE AI on September 17, 2026 at 18:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into the Route spec without validation or authorization checks. A namespace edit user, who normally cannot set custom Route hostnames, can use the operator as a confused deputy to claim arbitrary externally-routable hostnames, enabling subdomain takeover and, in combination with the auto-grant OAuthClient, OAuth redirect hijack.
Title Hawtio-operator: hawtio-operator: routes/custom-host confused-deputy via spec.routehostname
First Time appeared Redhat
Redhat apache Camel Hawtio
Weaknesses CWE-441
CPEs cpe:/a:redhat:apache_camel_hawtio:4
Vendors & Products Redhat
Redhat apache Camel Hawtio
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N'}


Subscriptions

Redhat Apache Camel Hawtio
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-15T17:52:24.958Z

Reserved: 2026-08-27T10:25:52.080Z

Link: CVE-2026-81303

cve-icon Vulnrichment

Updated: 2026-09-15T17:52:15.799Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T06:16:58.167

Modified: 2026-09-16T19:42:43.623

Link: CVE-2026-81303

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T05:09:48Z

Links: CVE-2026-81303 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')