A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configures M2M role mappings, the system uses unanchored regular expressions for matching claim values. This allows an attacker with a valid OpenID Connect (OIDC) token, whose claim value is a superstring of a configured pattern, to gain unauthorized access to roles they were not intended to receive. This can lead to privilege escalation within the system.
Metrics
Affected Vendors & Products
References
History
Mon, 10 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configures M2M role mappings, the system uses unanchored regular expressions for matching claim values. This allows an attacker with a valid OpenID Connect (OIDC) token, whose claim value is a superstring of a configured pattern, to gain unauthorized access to roles they were not intended to receive. This can lead to privilege escalation within the system. | |
| Title | Stackrox: stackrox: privilege escalation via unanchored regular expressions in auth m2m role mappings | |
| First Time appeared |
Redhat
Redhat advanced Cluster Security |
|
| Weaknesses | CWE-625 | |
| CPEs | cpe:/a:redhat:advanced_cluster_security:4 | |
| Vendors & Products |
Redhat
Redhat advanced Cluster Security |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-10T18:09:21.966Z
Reserved: 2026-08-07T15:16:51.217Z
Link: CVE-2026-19278
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-10T13:30:05Z