Information Disclosure Vulnerability in acm-search-v2-api-rhel9 by Red Hat
CVE-2026-71468
5.3MEDIUM
What is CVE-2026-71468?
A vulnerability exists in acm-search-v2-api-rhel9 where the getFederationConfig function incorrectly manages user session tokens. When the cache refreshes, it erroneously reuses a user's bearer token for all subsequent federated requests until the cache expires. This flaw permits other authenticated users to access sensitive remote managed hub search results, resulting in unauthorized information exposure.