A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the calling cluster. An attacker could exploit this by crafting specific user identifiers (UIDs) with a different cluster's prefix.
History

Thu, 20 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 19 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the calling cluster. An attacker could exploit this by crafting specific user identifiers (UIDs) with a different cluster's prefix.
Title Search-indexer: search-indexer: update/delete operations not scoped to caller's cluster (cross-tenant data tampering)
First Time appeared Redhat
Redhat acm
Weaknesses CWE-693
CPEs cpe:/a:redhat:acm:2
Vendors & Products Redhat
Redhat acm
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-19T20:56:17.608Z

Reserved: 2026-08-19T19:55:53.101Z

Link: CVE-2026-76827

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-19T21:17:39.227

Modified: 2026-08-19T21:17:39.227

Link: CVE-2026-76827

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-19T20:02:11Z

Links: CVE-2026-76827 - Bugzilla

cve-icon OpenCVE Enrichment

No data.