CVE-2026-71467: Red Hat Advanced Cluster Management For Kubernetes 2.17

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includes an `Upgrade: websocket` header. An unauthenticated attacker can exploit this by sending a specially crafted HTTP POST request to the `/federated` endpoint with the `Upgrade: websocket` header. This allows the attacker to bypass authentication and access federated search results across all configured remote managed hubs, leading to information disclosure.

Affected products

  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.17: before 1787229541 (fixed in 1787229541)

Published 2026-08-11. Last modified 2026-08-26.