Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Exclude logging sensitive info or apply masking. Set the operator log verbosity to 0 (the default) to prevent TLS key material from being written to logs. If debug logging has been enabled previously, rotate any TLS secrets that may have been exposed in the logs and purge the affected log entries from centralized logging systems.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 15 Sep 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object — including the TLS private key in PEM format — is serialized to JSON and written to the operator's standard output. Operator logs are typically forwarded to centralized logging systems and readable by anyone with pods/log access in the openshift-operators namespace. Debug level 1 is a low threshold commonly enabled during troubleshooting. | |
| Title | Hawtio-operator: hawtio-operator: tls private key written to operator log at debug level | |
| First Time appeared |
Redhat
Redhat apache Camel Hawtio |
|
| Weaknesses | CWE-532 | |
| CPEs | cpe:/a:redhat:apache_camel_hawtio:4 | |
| Vendors & Products |
Redhat
Redhat apache Camel Hawtio |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-15T05:35:37.603Z
Reserved: 2026-08-27T10:25:52.083Z
Link: CVE-2026-81320
No data.
Status : Received
Published: 2026-09-15T06:16:58.800
Modified: 2026-09-15T06:16:58.800
Link: CVE-2026-81320
OpenCVE Enrichment
No data.