Subdomain Takeover Vulnerability in Hawtio Operator by Red Hat
CVE-2026-81303
6.3MEDIUM
What is CVE-2026-81303?
A vulnerability exists in the Hawtio Operator that allows namespace edit users to leverage cluster-wide permissions associated with the operator. By doing so, they can claim arbitrary externally-routable hostnames through a lack of validation on the spec.routeHostName value input and circumventing standard authorization checks. This flaw potentially leads to subdomain takeovers and, when combined with the auto-grant OAuthClient feature, could result in unauthorized OAuth redirect hijacks, creating significant security risks for affected systems.