CVE-2026-10609: Openshift/cluster-logging-operator: cluster logging operator creates and forwards serviceaccount tokens without verifying clf creator authorization

Published Jun 2, 2026
·
Updated

A flaw was found in the OpenShift Cluster Logging Operator. The operator creates kubernetes.io/service-account-token Secrets and forwards them as bearer authentication to output URLs without verifying that the ClusterLogForwarder creator has authorization to use the referenced ServiceAccount's credentials. A user with write access to ClusterLogForwarder resources but without secrets access can exfiltrate ServiceAccount tokens for any in-namespace ServiceAccount. When a CLF specifies only receiver-type inputs, the SubjectAccessReview validation is bypassed entirely, widening the attack to SAs without log-collection RBAC. However, even with standard inputs, any SA that passes the input-side SAR check (including the operator's own SA) has its token created and forwarded without output-side authorization. The stolen token inherits all RBAC bindings of the target ServiceAccount, potentially enabling cluster-wide privilege escalation.

Other sources

A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying that the ClusterLogForwarder creator has permission to use those credentials, allowing a delegated editor to exfiltrate SA tokens and escalate privileges.

MITRE

Affected Software

3 affected components
Openshift OpenShift Cluster Logging Operator
redhat Cluster Logging Operator
redhat Logging Subsystem For Red Hat Openshift

Event History

Jun 2, 2026
Data Sourced
via Red Hat·12:01 PM
DescriptionSeverityAffected Software
Jun 23, 2026
CVE Published
via MITRE·01:26 PM
Data Sourced
via MITRE·01:26 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-10609?

CVE-2026-10609 has a medium severity rating of 6.8.

2

How do I fix CVE-2026-10609?

To fix CVE-2026-10609, ensure the OpenShift Cluster Logging Operator verifies ClusterLogForwarder creator authorization before creating and forwarding service account tokens.

3

What systems are affected by CVE-2026-10609?

CVE-2026-10609 affects OpenShift Cluster Logging Operator, specifically the versions in use within Red Hat OpenShift environments.

4

What type of vulnerability is CVE-2026-10609?

CVE-2026-10609 is a security flaw involving unauthorized forwarding of service account tokens.

5

When was CVE-2026-10609 published?

CVE-2026-10609 was published on June 2, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203