Impact
The flaw in search-indexer allows an authenticated managed cluster to perform UPDATE or DELETE operations on indexed search data that belong to a different cluster. It occurs because delta-sync write paths fail to restrict those modifications to data owned by the calling cluster. An attacker can craft user identifiers with another cluster’s prefix to target unrelated data, causing integrity loss or data deletion.
Affected Systems
Red Hat Advanced Cluster Management for Kubernetes version 2 (ACM 2). The vulnerability applies to all deployments of this product until a vendor patch is released.
Risk and Exploitability
The CVSS base score of 6.8 indicates moderate severity. EPSS data is unavailable, and the vulnerability is not yet listed in the CISA KEV catalog. Exploitation requires a registered and authenticated managed cluster with knowledge of another cluster’s UID prefix, making it an intra-tenant attack that may be limited to environments where multiple clusters coexist. While no public exploits are currently known, the ability to tamper with or delete search data could disrupt search services and compromise data integrity for affected tenants.
OpenCVE Enrichment