Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-80219
Red Hat Red Hat build of Apache Camel - HawtIO 4 — Hawtio-operator: hawtio-operator: oauthclient created with grantmethod auto and no secret enables oauth token theft
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L R C H H N 8.7 .0023 14.1 —
AFFECTED
Product Versions Fixed
Red Hat build of Apache Camel - HawtIO 4 unspecified —
Red Hat build of Apache Camel - HawtIO 4 unspecified —
TIMELINE
Aug 27 Reserved by redhat
Sep 8 Published (CNA: redhat)
Sep 21 REJECTED — CVE-2026-80219 (Red Hat build of Apache Camel - HawtIO 4). Record withdrawn by the CNA.
Description
Red Hat Product Security has come to the conclusion that this CVE is not needed.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| August 27, 2026 | Reserved | Reserved by redhat |
| September 8, 2026 | Published | Published (CNA: redhat) |
| September 21, 2026 | REJECTED | REJECTED — CVE-2026-80219 (Red Hat build of Apache Camel - HawtIO 4). Record withdrawn by the CNA. |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Red Hat | Red Hat build of Apache Camel - HawtIO 4 | — | — | — |
| Red Hat | Red Hat build of Apache Camel - HawtIO 4 | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-80219 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.