CVE-2026-76827: Red Hat Advanced Cluster Management For Kubernetes 2.11

Medium severity, CVSS 6.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the calling cluster. An attacker could exploit this by crafting specific user identifiers (UIDs) with a different cluster's prefix.

Affected products

  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.11: before 1787688957 (fixed in 1787688957)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.13: before 1787262474 (fixed in 1787262474)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.14: before 1787250074 (fixed in 1787250074)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.15: before 1787249293 (fixed in 1787249293)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.16: before 1787248491 (fixed in 1787248491)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.17: before 1787247085 (fixed in 1787247085)

Published 2026-08-19. Last modified 2026-09-05.