Authentication Bypass in Search-V2-API Affects Red Hat Products
CVE-2026-71467
7.5HIGH
What is CVE-2026-71467?
An issue has been identified in the search-v2-api component where the authentication middleware fails to perform proper checks when the 'Upgrade: websocket' header is present in requests. This vulnerability allows attackers to send crafted HTTP POST requests to the '/federated' endpoint, bypassing authentication entirely. Consequently, attackers can gain unauthorized access to sensitive federated search results from various remote managed hubs, leading to potential information disclosure and increased risks for affected systems.