Description
A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the calling cluster. An attacker could exploit this by crafting specific user identifiers (UIDs) with a different cluster's prefix.
Published: 2026-08-19
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in search-indexer allows an authenticated managed cluster to perform UPDATE or DELETE operations on indexed search data that belong to a different cluster. It occurs because delta-sync write paths fail to restrict those modifications to data owned by the calling cluster. An attacker can craft user identifiers with another cluster’s prefix to target unrelated data, causing integrity loss or data deletion.

Affected Systems

Red Hat Advanced Cluster Management for Kubernetes version 2 (ACM 2). The vulnerability applies to all deployments of this product until a vendor patch is released.

Risk and Exploitability

The CVSS base score of 6.8 indicates moderate severity. EPSS data is unavailable, and the vulnerability is not yet listed in the CISA KEV catalog. Exploitation requires a registered and authenticated managed cluster with knowledge of another cluster’s UID prefix, making it an intra-tenant attack that may be limited to environments where multiple clusters coexist. While no public exploits are currently known, the ability to tamper with or delete search data could disrupt search services and compromise data integrity for affected tenants.

Generated by OpenCVE AI on August 20, 2026 at 11:00 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Apply the official Red Hat security patch for ACM 2 as soon as it becomes available.
  • Since no official workaround exists, isolate search-indexer endpoints from unauthorized cross‑cluster access by applying network segmentation and restricting service ports to each cluster’s own namespace.
  • Regularly review Red Hat security advisories for any future mitigations or patches.

Generated by OpenCVE AI on August 20, 2026 at 11:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2.11::el9
cpe:/a:redhat:acm:2.14::el9
cpe:/a:redhat:acm:2.16::el9
References

Wed, 26 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2 cpe:/a:redhat:acm:2.13::el9
cpe:/a:redhat:acm:2.15::el9
cpe:/a:redhat:acm:2.17::el9
References

Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat advanced Cluster Management For Kubernetes
Vendors & Products Redhat advanced Cluster Management For Kubernetes

Fri, 21 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 19 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the calling cluster. An attacker could exploit this by crafting specific user identifiers (UIDs) with a different cluster's prefix.
Title Search-indexer: search-indexer: update/delete operations not scoped to caller's cluster (cross-tenant data tampering)
First Time appeared Redhat
Redhat acm
Weaknesses CWE-693
CPEs cpe:/a:redhat:acm:2
Vendors & Products Redhat
Redhat acm
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N'}


Subscriptions

Redhat Acm Advanced Cluster Management For Kubernetes
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-05T17:08:45.208Z

Reserved: 2026-08-19T19:55:53.101Z

Link: CVE-2026-76827

cve-icon Vulnrichment

Updated: 2026-08-21T16:49:11.427Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T21:17:39.227

Modified: 2026-09-05T18:17:29.027

Link: CVE-2026-76827

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-19T20:02:11Z

Links: CVE-2026-76827 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:16:12Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure