GHSA-9xm2-gw56-wj7m

Suggest an improvement
Source
https://github.com/advisories/GHSA-9xm2-gw56-wj7m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-9xm2-gw56-wj7m/GHSA-9xm2-gw56-wj7m.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9xm2-gw56-wj7m
Aliases
  • CVE-2026-10609
Published
2026-06-23T15:32:37Z
Modified
2026-09-24T19:15:05Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
OpenShift Cluster Logging Operator missing authorization flaw
Details

A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying that the ClusterLogForwarder creator has permission to use those credentials, allowing a delegated editor to exfiltrate SA tokens and escalate privileges.

Database specific
{
    "cwe_ids":  [
        "CWE-862"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-24T19:00:06Z",
    "nvd_published_at":  "2026-06-23T14:17:21Z",
    "severity":  "MODERATE"
}
References

Affected packages

Go / github.com/openshift/cluster-logging-operator

Package

Name
github.com/openshift/cluster-logging-operator
View open source insights on deps.dev
Purl
pkg:golang/github.com/openshift/cluster-logging-operator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.0-20260804174055-1864c2a9851d

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-9xm2-gw56-wj7m/GHSA-9xm2-gw56-wj7m.json"