Search-indexer: search-indexer: update/delete operations not scoped to caller's cluster (cross-tenant data tampering)
Summary
| CVE | CVE-2026-76827 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-19 21:17:39 UTC |
| Updated | 2026-09-05 18:17:29 UTC |
| Description | A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the calling cluster. An attacker could exploit this by crafting specific user identifiers (UIDs) with a different cluster's prefix. |
Risk And Classification
Primary CVSS: v3.1 6.8 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
EPSS: 0.003160000 probability, percentile 0.241090000 (date 2026-09-07)
Problem Types: CWE-693 | CWE-693 Protection Mechanism Failure
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 6.8 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N |
| 3.1 | CNA | CVSS | 6.8 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
ChangedConfidentiality
NoneIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Red Hat | Red Hat Advanced Cluster Management For Kubernetes 2.11 | unaffected 1787688957 * rpm | Not specified |
| CNA | Red Hat | Red Hat Advanced Cluster Management For Kubernetes 2.13 | unaffected 1787262474 * rpm | Not specified |
| CNA | Red Hat | Red Hat Advanced Cluster Management For Kubernetes 2.14 | unaffected 1787250074 * rpm | Not specified |
| CNA | Red Hat | Red Hat Advanced Cluster Management For Kubernetes 2.15 | unaffected 1787249293 * rpm | Not specified |
| CNA | Red Hat | Red Hat Advanced Cluster Management For Kubernetes 2.16 | unaffected 1787248491 * rpm | Not specified |
| CNA | Red Hat | Red Hat Advanced Cluster Management For Kubernetes 2.17 | unaffected 1787247085 * rpm | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/security/cve/CVE-2026-76827 | [email protected] | access.redhat.com | |
| bugzilla.redhat.com/show_bug.cgi | [email protected] | bugzilla.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60389 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60388 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60387 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60390 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60391 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60386 | [email protected] | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2026-08-19T19:36:45.000Z | Reported to Red Hat. |
| CNA | 2026-08-19T20:02:11.692Z | Made public. |
Workarounds
CNA: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
There are currently no legacy QID mappings associated with this CVE.