A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configures M2M role mappings, the system uses unanchored regular expressions for matching claim values. This allows an attacker with a valid OpenID Connect (OIDC) token, whose claim value is a superstring of a configured pattern, to gain unauthorized access to roles they were not intended to receive. This can lead to privilege escalation within the system.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 10 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configures M2M role mappings, the system uses unanchored regular expressions for matching claim values. This allows an attacker with a valid OpenID Connect (OIDC) token, whose claim value is a superstring of a configured pattern, to gain unauthorized access to roles they were not intended to receive. This can lead to privilege escalation within the system. | |
| Title | Stackrox: stackrox: privilege escalation via unanchored regular expressions in auth m2m role mappings | |
| First Time appeared |
Redhat
Redhat advanced Cluster Security |
|
| Weaknesses | CWE-625 | |
| CPEs | cpe:/a:redhat:advanced_cluster_security:4 | |
| Vendors & Products |
Redhat
Redhat advanced Cluster Security |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2026-08-10T12:13:40.169Z
Updated: 2026-08-11T06:25:18.312Z
Reserved: 2026-08-07T15:16:51.217Z
Link: CVE-2026-19278
Updated: 2026-08-10T18:09:13.914Z
Status : Awaiting Analysis
Published: 2026-08-10T13:17:58.797
Modified: 2026-08-14T19:07:46.080
Link: CVE-2026-19278