Search-Indexer Vulnerability in Red Hat Managed Clusters
CVE-2026-76827
6.8MEDIUM
Key Information:
What is CVE-2026-76827?
A critical flaw exists in the search-indexer component of Red Hat Managed Clusters, enabling authenticated users to manipulate or erase indexed search data from other clusters. This vulnerability arises due to improper restrictions in the delta-sync write paths, which fail to enforce owner permissions on UPDATE and DELETE operations. As a result, an attacker may exploit this flaw by generating user identifiers (UIDs) that correspond to a different cluster, allowing unauthorized access to sensitive data.
Affected Version(s)
Red Hat Advanced Cluster Management for Kubernetes 2.11 1787688957
Red Hat Advanced Cluster Management for Kubernetes 2.13 1787262474
Red Hat Advanced Cluster Management for Kubernetes 2.14 1787250074