Unanchored regex in RHACS Central M2M token exchange allows privilege escalation
CVE-2026-19278 Published on August 10, 2026
Stackrox: stackrox: privilege escalation via unanchored regular expressions in auth m2m role mappings
A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configures M2M role mappings, the system uses unanchored regular expressions for matching claim values. This allows an attacker with a valid OpenID Connect (OIDC) token, whose claim value is a superstring of a configured pattern, to gain unauthorized access to roles they were not intended to receive. This can lead to privilege escalation within the system.
Vulnerability Analysis
CVE-2026-19278 is exploitable with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
Permissive Regular Expression
The product uses a regular expression that does not sufficiently restrict the set of allowed values.
Products Associated with CVE-2026-19278
Want to know whenever a new CVE is published for Red Hat Advanced Cluster Security? stack.watch will email you.