# CVE-2026-49332

## Summary

- **CVE ID:** CVE-2026-49332
- **Severity:** HIGH
- **CVSS Score:** 8.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N)
- **CWE:** CWE-436
- **Published:** Jul 28, 2026
- **Last Modified:** Sep 8, 2026

## Description

A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application.

## Affected Products

- Red Hat — Red Hat OpenShift Container Platform 4.21 (1785851359)
- Red Hat — Red Hat OpenShift Container Platform 4.20 (1785833742)
- Red Hat — Red Hat OpenShift Container Platform 4.22 (1785885351)
- Red Hat — Red Hat OpenShift Container Platform 4.18 (1785529735)
- Red Hat — Red Hat OpenShift Container Platform 4.19 (1785521728)
- Red Hat — Red Hat OpenShift Container Platform 4.14 (1785549818)
- Red Hat — Red Hat OpenShift Container Platform 4.16 (1785544039)
- Red Hat — Red Hat OpenShift Container Platform 4.2 (1785833742)
- Red Hat — Red Hat OpenShift Container Platform 4.12 (1786458704)
- Red Hat — Red Hat OpenShift Container Platform 4.13 (1786477436)
- Red Hat — Red Hat OpenShift Container Platform 4.15 (1787054100)
- Red Hat — Red Hat OpenShift Container Platform 4.17 (1787543313)

## References

- [CNA](https://access.redhat.com/security/cve/CVE-2026-49332)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=2483253)
- [CNA](https://access.redhat.com/errata/RHSA-2026:51025)
- [CNA](https://access.redhat.com/errata/RHSA-2026:51022)
- [CNA](https://access.redhat.com/errata/RHSA-2026:51038)
- [CNA](https://access.redhat.com/errata/RHSA-2026:51007)
- [CNA](https://access.redhat.com/errata/RHSA-2026:51013)
- [CNA](https://access.redhat.com/errata/RHSA-2026:50681)
- [CNA](https://access.redhat.com/errata/RHSA-2026:50758)
- [CNA](https://access.redhat.com/errata/RHSA-2026:54206)
- [CNA](https://access.redhat.com/errata/RHSA-2026:54188)
- [CNA](https://access.redhat.com/errata/RHSA-2026:56912)
- [CNA](https://access.redhat.com/errata/RHSA-2026:60023)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.30%
- **EPSS Percentile:** 22.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-12._