A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access to remote managed hub search results, leading to information disclosure.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access to remote managed hub search results, leading to information disclosure. | |
| Title | Acm-search-v2-api-rhel9: search-v2-api: cross-user bearer-token reuse via global federation-config cache | |
| First Time appeared |
Redhat
Redhat acm |
|
| Weaknesses | CWE-266 | |
| CPEs | cpe:/a:redhat:acm:2 | |
| Vendors & Products |
Redhat
Redhat acm |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-11T19:24:21.036Z
Reserved: 2026-08-06T19:34:07.969Z
Link: CVE-2026-71468
No data.
Status : Received
Published: 2026-08-11T20:18:45.410
Modified: 2026-08-11T20:18:45.410
Link: CVE-2026-71468
No data.
OpenCVE Enrichment
No data.