Junglewise Threat Intelligence

CVE-2026-19278: Red Hat Advanced Cluster Security privilege escalation in M2M auth

CVE-2026-19278 · Severity: medium · CVSS 6.8 · Published 2026-08-10

Technologies: Red Hat Advanced Cluster Security for Kubernetes. Vendors: Red Hat.

Executive brief

Red Hat Advanced Cluster Security (RHACS) is a Kubernetes security platform used to monitor and protect containerized applications. A flaw in its machine-to-machine token authentication system allows attackers with valid credentials to bypass role restrictions and gain unauthorized administrative privileges, potentially compromising container security policies and access controls across an organization's Kubernetes infrastructure.

Technical details

The vulnerability is a permissive regular expression (CWE-625) flaw in RHACS Central's machine-to-machine (M2M) OIDC token exchange mechanism. When administrators configure M2M role mappings, the system fails to anchor regex patterns (missing `^` and ` Junglewise delimiters), enabling substring matching instead of exact claim value matching. An attacker with a valid OIDC token from a trusted identity provider can craft a claim value that partially matches a configured pattern, bypassing intended role restrictions. This requires both a valid OIDC token and an unanchored pattern in the admin configuration; exploitation leads to privilege escalation and unauthorized role assignment. Mitigation involves updating role mapping expressions to use properly anchored regex patterns.

Affected products

  • Red Hat Advanced Cluster Security for Kubernetes <UNKNOWN>

Timeline

  • 2026-08-10: disclosed

References

Related threats