Junglewise Threat Intelligence

CVE-2026-15812: kronosnet ACL bypass via link ID spoofing on unencrypted dynamic links

CVE-2026-15812 · Severity: medium · CVSS 4.8 · Published 2026-07-21

Technologies: Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, Kronosnet, Red Hat Enterprise Linux 10. Vendors: Red Hat, Kronosnet.

Executive brief

Kronosnet, a networking tool used to connect multiple computers in a cluster, contains a security flaw in how it verifies incoming data. When configured to accept connections from any address without encryption, the system fails to properly check if the sender is who they claim to be. An attacker could exploit this to bypass security controls and send unauthorized data into the network, potentially causing data corruption or system crashes.

Technical details

A logical flaw exists in the internal Access Control List (ACL) subsystem of kronosnet when configured to manage dynamic links without network payload encryption. The validation architecture implicitly trusts the link ID provided within incoming data packets without cryptographic verification. A remote, unauthenticated attacker can exploit this by spoofing a legitimate link ID inside crafted network frames. This allows the attacker to bypass the ACL framework and inject arbitrary data packets into the application layer, potentially leading to data corruption or service instability. The vulnerability affects kronosnet versions 1.34 and earlier.

Affected products

  • kronosnet kronosnet <= 1.34
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9
  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat OpenShift Container Platform 4

Timeline

  • 2026-07-15: disclosed: Reported to Red Hat Bugzilla
  • 2026-07-21: advisory: NVD publication date

References

Related threats