# CVE-2026-1784

## Summary

- **CVE ID:** CVE-2026-1784
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-15
- **Published:** Jun 2, 2026
- **Last Modified:** Sep 10, 2026

## Description

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.

## Affected Products

- Red Hat — Red Hat OpenShift Container Platform 4.19 (1780043338)
- Red Hat — Red Hat OpenShift Container Platform 4.21 (1780444348)
- Red Hat — Red Hat OpenShift Container Platform 4.20 (1780990977)
- Red Hat — Red Hat OpenShift Container Platform 4.16 (1780962617)
- Red Hat — Red Hat OpenShift Container Platform 4.18 (1780988280)
- Red Hat — Red Hat OpenShift Container Platform 4.13 (1781123014)
- Red Hat — Red Hat OpenShift Container Platform 4.14 (1781870101)
- Red Hat — Red Hat OpenShift Container Platform 4.15 (1781928857)
- Red Hat — Red Hat OpenShift Container Platform 4.2 (1780990977)

## References

- [CNA](https://access.redhat.com/security/cve/CVE-2026-1784)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=2436075)
- [CNA](https://access.redhat.com/errata/RHSA-2026:23246)
- [CNA](https://access.redhat.com/errata/RHSA-2026:23241)
- [CNA](https://access.redhat.com/errata/RHSA-2026:25194)
- [CNA](https://access.redhat.com/errata/RHSA-2026:25045)
- [CNA](https://access.redhat.com/errata/RHSA-2026:25182)
- [CNA](https://access.redhat.com/errata/RHSA-2026:26543)
- [redhat-SADP](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1784.json)
- [CNA](https://access.redhat.com/errata/RHSA-2026:28893)
- [CNA](https://access.redhat.com/errata/RHSA-2026:28964)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.19%
- **EPSS Percentile:** 9.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._