Description
A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object — including the TLS private key in PEM format — is serialized to JSON and written to the operator's standard output. Operator logs are typically forwarded to centralized logging systems and readable by anyone with pods/log access in the openshift-operators namespace. Debug level 1 is a low threshold commonly enabled during troubleshooting.
Published: 2026-09-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Exposure
Action: Apply Workaround
AI Analysis

Impact

A flaw in the hawtio-operator causes the entire Route object, including the TLS private key in PEM format, to be serialized to JSON and written to the operator’s standard output when debug log level 1 or higher is enabled. The exposure of private key material constitutes a confidentiality breach, potentially allowing an attacker to decrypt traffic or impersonate the service. The vulnerability is a classic example of sensitive data exposure via logging (CWE-532).

Affected Systems

Red Hat build of Apache Camel – HawtIO 4 is affected. No specific sub‑versions are listed; all installations of this product that enable debug logging at level 1 or higher are at risk.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate severity. The EPSS score is below 1 %, indicating that exploitation is unlikely but possible. The vulnerability is not listed in the CISA KEV catalog, so there is no known active exploitation yet. The attack vector is local to the operator pod: an attacker with access to pod logs (e.g., anyone with pod/log permissions in the openshift‑operators namespace) can retrieve the exposed key. The requirement of debug logging is a low threshold commonly enabled during troubleshooting, so the risk is elevated in environments where debugging is used frequently.

Generated by OpenCVE AI on September 17, 2026 at 18:48 UTC.

Remediation

Vendor Workaround

Exclude logging sensitive info or apply masking. Set the operator log verbosity to 0 (the default) to prevent TLS key material from being written to logs. If debug logging has been enabled previously, rotate any TLS secrets that may have been exposed in the logs and purge the affected log entries from centralized logging systems.


OpenCVE Recommended Actions

  • Set the operator log verbosity to 0 (the default) to prevent TLS key material from being written to logs.
  • If debug logging was previously enabled, rotate the TLS secrets used by the Route and purge any logs that may have captured the key from centralized logging systems.
  • Ensure that access to operator logs is restricted to authorized personnel only, minimizing the chances of an attacker reading the exposed key.

Generated by OpenCVE AI on September 17, 2026 at 18:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object — including the TLS private key in PEM format — is serialized to JSON and written to the operator's standard output. Operator logs are typically forwarded to centralized logging systems and readable by anyone with pods/log access in the openshift-operators namespace. Debug level 1 is a low threshold commonly enabled during troubleshooting.
Title Hawtio-operator: hawtio-operator: tls private key written to operator log at debug level
First Time appeared Redhat
Redhat apache Camel Hawtio
Weaknesses CWE-532
CPEs cpe:/a:redhat:apache_camel_hawtio:4
Vendors & Products Redhat
Redhat apache Camel Hawtio
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Redhat Apache Camel Hawtio
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-17T18:28:30.115Z

Reserved: 2026-08-27T10:25:52.083Z

Link: CVE-2026-81320

cve-icon Vulnrichment

Updated: 2026-09-17T18:28:13.839Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T06:16:58.800

Modified: 2026-09-17T19:17:03.423

Link: CVE-2026-81320

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T05:11:15Z

Links: CVE-2026-81320 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File