Authentication Bypass in Search-V2-API Affects Red Hat Products
CVE-2026-71467

7.5HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
11 August 2026

What is CVE-2026-71467?

An issue has been identified in the search-v2-api component where the authentication middleware fails to perform proper checks when the 'Upgrade: websocket' header is present in requests. This vulnerability allows attackers to send crafted HTTP POST requests to the '/federated' endpoint, bypassing authentication entirely. Consequently, attackers can gain unauthorized access to sensitive federated search results from various remote managed hubs, leading to potential information disclosure and increased risks for affected systems.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.