{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/hawtio-operator/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hawtio:hawtio-operator:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-77968"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["hawtio-operator"],"_cs_severities":["high"],"_cs_tags":["oauth","privilege-escalation","token-harvesting","cloud-security"],"_cs_type":"advisory","_cs_vendors":["Hawtio"],"content_html":"\u003cp\u003eCVE-2026-77968 describes a security vulnerability in the hawtio-operator involving excessive RBAC permissions. The operator's associated ClusterRole grants the ServiceAccount broad permissions to create, get, list, update, and watch Kubernetes Secrets across all namespaces. Although the operator employs a controller-runtime label-selector cache as a memory optimization, the underlying ServiceAccount token possesses direct, unrestricted access to the Kubernetes API. An attacker who successfully achieves code execution within the hawtio-operator pod can leverage these permissions to bypass cache restrictions via direct API queries, allowing for the unauthorized exfiltration of sensitive information including cloud credentials, service account tokens, and other operator secrets. This flaw significantly expands the impact of a container compromise to a full cluster-wide secret exposure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-77968 allows an attacker with pod-level access to escalate privileges to the cluster level by retrieving all stored Secrets. This includes sensitive bootstrap tokens, cloud provider credentials, and secrets belonging to other workloads. Potential consequences include full lateral movement, persistence across the cluster environment, and exfiltration of sensitive data protected by the Kubernetes Secret API.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAudit current Kubernetes RBAC configurations to identify and restrict excessive permissions for the hawtio-operator ServiceAccount.\u003c/li\u003e\n\u003cli\u003eImplement Principle of Least Privilege by constraining ClusterRole permissions to specific namespaces or resources rather than the entire cluster scope, as referenced by CVE-2026-77968.\u003c/li\u003e\n\u003cli\u003eMonitor API server audit logs for anomalous 'list' or 'get' requests on resources of type 'secrets' originating from the hawtio-operator ServiceAccount identity.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-08T13:41:01Z","date_published":"2026-09-08T13:40:54Z","id":"https://feed.craftedsignal.io/briefs/2026-09-hawtio-operator-privesc/","summary":"The hawtio-operator contains an overly permissive ClusterRole configuration that enables an attacker who compromises the operator pod to access all Secrets across the Kubernetes cluster.","title":"Excessive ClusterRole Permissions in hawtio-operator","url":"https://feed.craftedsignal.io/briefs/2026-09-hawtio-operator-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - Hawtio-Operator","version":"https://jsonfeed.org/version/1.1"}