CVE-2026-81303
A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into the Route spec without validation or authorization checks. A namespace edit user, who normally cannot set custom Route hostnames, can use the operator as a confused deputy to claim arbitrary externally-routable hostnames, enabling subdomain takeover and, in combination with the auto-grant OAuthClient, OAuth redirect hijack.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
- EPSS probability
- 0.27%
- CWE
- CWE-441
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Weakness type
Related vulnerabilities
- CVE-2026-83548 — A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended altern
- CVE-2025-68667 — Conduit-derived homeservers are affected by a Confused Deputy and Improper Input Validation issue
- CVE-2026-87582 — Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised th
- CVE-2025-64125 — Nuvation Energy nCloud Client-to-Client Communication
- CVE-2026-24471 — Improper Validation in Conduit-derived homeservers resulting in Unintended Proxy or Intermediary ('Confused Deputy')
- CVE-2025-25306 — Misskey's Incomplete Patch of CVE-2024-52591 Leads to Forgery of Federated Notes
- CVE-2022-39361 — Metabase vulnerable to Remote Code Execution via H2
- CVE-2021-32783 — Authorization bypass in Contour