A flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-scoped OAuthClient with automatic grant approval (GrantMethod: auto) and no client secret (public client). The redirect URIs are derived from the operator-created Route, whose hostname is tenant-controlled via the Hawtio CR spec.routeHostName field. A malicious tenant can register an arbitrary hostname as a valid OAuth redirect target and, because grants are auto-approved, obtain OpenShift access tokens of any cluster user who visits the crafted authorization URL without any consent prompt.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-80219 exploits a critical misconfiguration in hawtio-operator's cluster-mode deployment where OAuth clients are created with automatic grant approval and no client secret validation. The vulnerability allows malicious tenants to manipulate the Hawtio CR spec.routeHostName field to register arbitrary hostnames as valid OAuth redirect targets. Since the operator auto-approves OAuth grants without proper validation, an attacker can redirect legitimate authentication flows to attacker-controlled endpoints and capture OpenShift API tokens. This affects any organization deploying hawtio-operator in multi-tenant Kubernetes clusters where tenant-controlled specifications can influence security-critical OAuth configurations.
While this CVE doesn't map to specific MITRE ATT&CK techniques in the current threat framework, Casky's security skills would detect the underlying attack patterns through analysis of OAuth configuration anomalies and credential access attempts. Practitioners using Casky would identify suspicious patterns including: unauthorized Route hostname modifications, OAuth client configuration drift from baseline policies, unexpected redirect URI registrations pointing to external domains, and token exfiltration attempts following authentication flows. Claude's extended reasoning capabilities would correlate these indicators to surface the attack chain—from initial tenant access through configuration manipulation to final token capture—enabling security teams to detect compromised deployments before tokens are exploited for persistent cluster access.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-80219. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation