What is CVE-2026-19278?
A vulnerability was found in StackRox/RHACS Central's M2M token exchange where unanchored regular expressions in role mappings allow an attacker with a valid OIDC token to bypass authorization by manipulating claim values. This could lead to privilege escalation through crafted token claims. Users should review their M2M mappings and ensure regex patterns use `^` and `$` anchors until an official patch is applied.
Azərbaycanca: StackRox/RHACS Central-da M2M token mübadiləsi zamanı rol xəritələnməsi üçün istifadə olunan regex-lərin lövbərlənməməsi səbəbindən autentifikasiya bypass zəifliyi aşkar edilib. Bu, etibarlı OIDC tokeninə malik hücumçuya iddia dəyərlərini manipulyasiya edərək icazəsiz imtiyazlar əldə etməyə imkan verir. İstifadəçilərə rəsmi patch tətbiq edilənə qədər M2M rol xəritələndirmələrini nəzərdən keçirmək və regex-lərdə `^` ilə `$` lövbərlərindən istifadə etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
What does an attacker need to exploit the CVE-2026-19278 vulnerability?
An attacker must have a valid OIDC token to manipulate claim values and gain unauthorized privileges.
How can StackRox/RHACS users mitigate the CVE-2026-19278 risk before an official patch is applied?
Users should review their M2M role mappings and ensure regex patterns use `^` and `$` anchors.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.