Medium severity6.8NVD Advisory· Published Aug 10, 2026
CVE-2026-19278
CVE-2026-19278
Description
A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configures M2M role mappings, the system uses unanchored regular expressions for matching claim values. This allows an attacker with a valid OpenID Connect (OIDC) token, whose claim value is a superstring of a configured pattern, to gain unauthorized access to roles they were not intended to receive. This can lead to privilege escalation within the system.
Affected products
2Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.