# CVE-2026-80219

## Summary

- **CVE ID:** CVE-2026-80219
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N)
- **CWE:** CWE-1390
- **Published:** Sep 8, 2026
- **Last Modified:** Sep 8, 2026

## Description

A flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-scoped OAuthClient with automatic grant approval (GrantMethod: auto) and no client secret (public client). The redirect URIs are derived from the operator-created Route, whose hostname is tenant-controlled via the Hawtio CR spec.routeHostName field. A malicious tenant can register an arbitrary hostname as a valid OAuth redirect target and, because grants are auto-approved, obtain OpenShift access tokens of any cluster user who visits the crafted authorization URL without any consent prompt.

## Affected Products

No affected products listed.

## References

- [CNA](https://access.redhat.com/security/cve/CVE-2026-80219)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=2524895)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.23%
- **EPSS Percentile:** 13.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._