Information Disclosure Vulnerability in acm-search-v2-api-rhel9 by Red Hat
CVE-2026-71468

5.3MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
11 August 2026

What is CVE-2026-71468?

A vulnerability exists in acm-search-v2-api-rhel9 where the getFederationConfig function incorrectly manages user session tokens. When the cache refreshes, it erroneously reuses a user's bearer token for all subsequent federated requests until the cache expires. This flaw permits other authenticated users to access sensitive remote managed hub search results, resulting in unauthorized information exposure.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.