Search-Indexer Vulnerability in Red Hat Managed Clusters
CVE-2026-76827
6.8MEDIUM
What is CVE-2026-76827?
A critical flaw exists in the search-indexer component of Red Hat Managed Clusters, enabling authenticated users to manipulate or erase indexed search data from other clusters. This vulnerability arises due to improper restrictions in the delta-sync write paths, which fail to enforce owner permissions on UPDATE and DELETE operations. As a result, an attacker may exploit this flaw by generating user identifiers (UIDs) that correspond to a different cluster, allowing unauthorized access to sensitive data.