Unanchored regex in RHACS Central M2M token exchange allows privilege escalation
CVE-2026-19278 Published on August 10, 2026

Stackrox: stackrox: privilege escalation via unanchored regular expressions in auth m2m role mappings
A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configures M2M role mappings, the system uses unanchored regular expressions for matching claim values. This allows an attacker with a valid OpenID Connect (OIDC) token, whose claim value is a superstring of a configured pattern, to gain unauthorized access to roles they were not intended to receive. This can lead to privilege escalation within the system.

NVD

Vulnerability Analysis

CVE-2026-19278 is exploitable with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
NONE

Timeline

Reported to Red Hat.

Made public.

Weakness Type

Permissive Regular Expression

The product uses a regular expression that does not sufficiently restrict the set of allowed values.


Products Associated with CVE-2026-19278

Want to know whenever a new CVE is published for Red Hat Advanced Cluster Security? stack.watch will email you.

 

Affected Versions

Red Hat Advanced Cluster Security 4: