Search-Indexer Vulnerability in Red Hat Managed Clusters
CVE-2026-76827

6.8MEDIUM

What is CVE-2026-76827?

A critical flaw exists in the search-indexer component of Red Hat Managed Clusters, enabling authenticated users to manipulate or erase indexed search data from other clusters. This vulnerability arises due to improper restrictions in the delta-sync write paths, which fail to enforce owner permissions on UPDATE and DELETE operations. As a result, an attacker may exploit this flaw by generating user identifiers (UIDs) that correspond to a different cluster, allowing unauthorized access to sensitive data.

Affected Version(s)

Red Hat Advanced Cluster Management for Kubernetes 2.11 1787688957

Red Hat Advanced Cluster Management for Kubernetes 2.13 1787262474

Red Hat Advanced Cluster Management for Kubernetes 2.14 1787250074

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.