← All Advisories

CVE-2026-1784

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-1784

Key Details

CVECVE-2026-1784
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-10-01
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-15 (External Control of System or Configuration Setting)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatOpenShift Container Platform
Red HatRed Hat OpenShift Container Platform 4.12
Red HatRed Hat OpenShift Container Platform 4.13
Red HatRed Hat OpenShift Container Platform 4.14
Red HatRed Hat OpenShift Container Platform 4.15
Red HatRed Hat OpenShift Container Platform 4.16
Red HatRed Hat OpenShift Container Platform 4.18
Red HatRed Hat OpenShift Container Platform 4.19
Red HatRed Hat OpenShift Container Platform 4.20
Red HatRed Hat OpenShift Container Platform 4.21
SubsystemsCore Infrastructure
SectorsMultiple

What to Know

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-1784
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-1784
Vendor advisoryhttps://access.redhat.com/security/cve/CVE-2026-1784