Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-81320— Hawtio-operator: hawtio-operator: tls private key written to operator log at debug level

Quick assessment

Affected
Red Hat Red Hat build of Apache Camel - HawtIO 4
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

漏洞描述: 在 hawtio-operator 中发现一个缺陷。当配置了自定义的 Route TLS 密钥(secret),且操作符(operator)运行在调试日志级别 1 或更高时,整个 Route 对象——包括以 PEM 格式存储的 TLS 私钥——会被序列化为 JSON 并写入操作符的标准输出。由于操作符的日志通常会被转发到集中式日志系统,任何拥有 openshift-operators 命名空间中 Pod 日志访问权限的用户都可能读取到这些日志。而调试级别 1 是一个较低的阈值,在故障排查时常常会被启用。

CVSS 5.5 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81320

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Hawtio-operator: hawtio-operator: tls private key written to operator log at debug level
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object — including the TLS private key in PEM format — is serialized to JSON and written to the operator's standard output. Operator logs are typically forwarded to centralized logging systems and readable by anyone with pods/log access in the openshift-operators namespace. Debug level 1 is a low threshold commonly enabled during troubleshooting.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过日志文件的信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat build of Apache Camel - HawtIO 4 - cpe:/a:redhat:apache_camel_hawtio:4

II. Public POCs for CVE-2026-81320

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81320

登录查看更多情报信息。

Vendor Advisories for CVE-2026-81320 (1)

Other References for CVE-2026-81320 (1)

Same Patch Batch · Red Hat · 2026-09-15 · 4 CVEs total

CVE-2026-75092 7.3 HIGH Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysqld
CVE-2026-81303 6.3 MEDIUM Hawtio-operator: hawtio-operator: routes/custom-host confused-deputy via spec.routehostnam
CVE-2026-91786 6.1 MEDIUM Gnome-shell: gnome-shell: out-of-bounds read in remote search icon rendering due to unvali

IV. Related Vulnerabilities

V. Comments for CVE-2026-81320

No comments yet


Leave a comment