← All Advisories

CVE-2026-49332

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-49332

Key Details

CVECVE-2026-49332
CVSS Score / Version8.5 (High) / CVSS v3.1
Updated2026-09-21
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is low; availability impact is none.
Affected productssee table below
Classified asCWE-436 (Interpretation Conflict)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat OpenShift Container Platform 4.12
Red HatRed Hat OpenShift Container Platform 4.13
Red HatRed Hat OpenShift Container Platform 4.14
Red HatRed Hat OpenShift Container Platform 4.15
Red HatRed Hat OpenShift Container Platform 4.16
Red HatRed Hat OpenShift Container Platform 4.17
Red HatRed Hat OpenShift Container Platform 4.18
Red HatRed Hat OpenShift Container Platform 4.19
Red HatRed Hat OpenShift Container Platform 4.20
Red HatRed Hat OpenShift Container Platform 4.21
Red HatRed Hat OpenShift Container Platform 4.22
SubsystemsGeneral OT
SectorsMultiple

What to Know

A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-49332
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-49332