PatchSiren cyber security CVE debrief
CVE-2026-49332 Red Hat CVE debrief
A flaw in openshift/oauth-proxy allows an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application. This issue is specific to the handling of dash-variant and underscore-variant keys in headers. The vulnerability can be exploited by an attacker with low privileges, potentially leading to unauthorized access or privilege escalation in OpenShift Container Platform 4.20 deployments. Defenders should assess exposure and prioritize remediation based on Red Hat errata.
- Vendor
- Red Hat
- Product
- Red Hat OpenShift Container Platform 4.20
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-28
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-07-28
- Advisory updated
- 2026-09-21
Who should care
Defenders responsible for OpenShift Container Platform 4.20 deployments, particularly those managing authentication and authorization configurations, should assess exposure and potential impact on upstream applications.
Why it matters
CVE-2026-49332 allows low-privilege users to smuggle forged identities, potentially overriding legitimate authenticated ones in OpenShift Container Platform 4.20 deployments. Defenders should verify exposure, assess impact on upstream applications, and prioritize remediation based on Red Hat errata.
- Verification of exposure in OpenShift Container Platform 4.20 deployments
- Assessment of potential identity smuggling impact on upstream applications
- Review and application of Red Hat errata related to this issue
- Monitoring for potential exploitation attempts
Technical summary
The openshift/oauth-proxy sets authenticated identity headers using dash-variant keys but does not strip underscore-variant keys from incoming requests. This allows an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application. The vulnerability is specific to the handling of dash-variant and underscore-variant keys in headers, and it can be exploited by an attacker with low privileges, potentially leading to unauthorized access or privilege escalation.
Defensive priority
Defenders should prioritize verifying exposure in OpenShift Container Platform 4.20 deployments and assessing the impact of identity smuggling on upstream applications.
Recommended defensive actions
- Verify OpenShift Container Platform 4.20 deployments for exposure to this vulnerability
- Assess the impact of identity smuggling on upstream applications
- Review and apply Red Hat errata related to this issue
- Monitor for potential exploitation attempts
- Implement compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in openshift/oauth-proxy. Red Hat has released several errata related to this issue, indicating affected and potentially fixed versions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-49332 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-49332
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-49332 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49332
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:50681
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:50758
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:51007
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:51013
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:51022
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:51025
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:51038
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:54188
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.