Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-81303— Hawtio-operator: hawtio-operator: routes/custom-host confused-deputy via spec.routehostname

Quick assessment

Affected
Red Hat Red Hat build of Apache Camel - HawtIO 4
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

hawtio-operator 中存在一个缺陷。该操作符在整个集群范围内拥有 权限,并且直接将 Hawtio 自定义资源中由租户提供的 值写入 Route 规范中,且未进行任何验证或授权检查。通常情况下,命名空间的编辑者无法设置自定义 Route 主机名,但他们可以利用该操作符作为“混淆代理”(confused deputy),从而声明任意外部可路由的主机名。这可能导致子域名接管(subdomain takeover)漏洞,并结合自动授予的 OAuthClient 权限,进一步引发 OAuth 重定向劫持(OAut

CVSS 6.3 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81303

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Hawtio-operator: hawtio-operator: routes/custom-host confused-deputy via spec.routehostname
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into the Route spec without validation or authorization checks. A namespace edit user, who normally cannot set custom Route hostnames, can use the operator as a confused deputy to claim arbitrary externally-routable hostnames, enabling subdomain takeover and, in combination with the auto-grant OAuthClient, OAuth redirect hijack.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
未有动机的代理或中间人(混淆代理)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat build of Apache Camel - HawtIO 4 - cpe:/a:redhat:apache_camel_hawtio:4
Red Hat Red Hat build of Apache Camel - HawtIO 4 - cpe:/a:redhat:apache_camel_hawtio:4

II. Public POCs for CVE-2026-81303

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81303

登录查看更多情报信息。

Vendor Advisories for CVE-2026-81303 (1)

Other References for CVE-2026-81303 (1)

Same Patch Batch · Red Hat · 2026-09-15 · 4 CVEs total

CVE-2026-75092 7.3 HIGH Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysqld
CVE-2026-91786 6.1 MEDIUM Gnome-shell: gnome-shell: out-of-bounds read in remote search icon rendering due to unvali
CVE-2026-81320 5.5 MEDIUM Hawtio-operator: hawtio-operator: tls private key written to operator log at debug level

IV. Related Vulnerabilities

V. Comments for CVE-2026-81303

No comments yet


Leave a comment