CVE-2026-76827: Red Hat Advanced Cluster Management For Kubernetes 2.11
Medium severity, CVSS 6.8. EPSS: 0.5% chance of exploitation in the next 30 days.
A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the calling cluster. An attacker could exploit this by crafting specific user identifiers (UIDs) with a different cluster's prefix.
Affected products
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.11: before 1787688957 (fixed in 1787688957)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.13: before 1787262474 (fixed in 1787262474)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.14: before 1787250074 (fixed in 1787250074)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.15: before 1787249293 (fixed in 1787249293)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.16: before 1787248491 (fixed in 1787248491)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.17: before 1787247085 (fixed in 1787247085)
Published 2026-08-19. Last modified 2026-09-05.