A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the calling cluster. An attacker could exploit this by crafting specific user identifiers (UIDs) with a different cluster's prefix.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 19 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the calling cluster. An attacker could exploit this by crafting specific user identifiers (UIDs) with a different cluster's prefix. | |
| Title | Search-indexer: search-indexer: update/delete operations not scoped to caller's cluster (cross-tenant data tampering) | |
| First Time appeared |
Redhat
Redhat acm |
|
| Weaknesses | CWE-693 | |
| CPEs | cpe:/a:redhat:acm:2 | |
| Vendors & Products |
Redhat
Redhat acm |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-19T20:56:17.608Z
Reserved: 2026-08-19T19:55:53.101Z
Link: CVE-2026-76827
No data.
Status : Received
Published: 2026-08-19T21:17:39.227
Modified: 2026-08-19T21:17:39.227
Link: CVE-2026-76827
OpenCVE Enrichment
No data.