CVE-2026-71468
Awaiting Analysis Awaiting Analysis - Queue

ACM Search V2 API Bearer Token Cache Information Disclosure

Vulnerability report for CVE-2026-71468, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-27

Assigner: redhat-SADP

Description

A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access to remote managed hub search results, leading to information disclosure.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-27
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
red_hat advanced_cluster_management_for_kubernetes From 2.0.0 (inc)
red_hat acm-search-v2-api-rhel9 *
stolostron search-v2-api *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Red Hat Advanced Cluster Management for Kubernetes, specifically the acm-search-v2-api-rhel9 component. The getFederationConfig function improperly reuses a user's bearer token when refreshing its cache. This allows other authenticated users to access unauthorized remote managed hub search results, leading to information disclosure.

Detection Guidance

To detect this vulnerability, check if the FEATURE_FEDERATED_SEARCH flag is enabled in your Red Hat Advanced Cluster Management for Kubernetes deployment. Review logs for the acm-search-v2-api-rhel9 component to identify bearer token reuse across users during cache refreshes. Look for unauthorized access to remote managed hub search results by different users.

Impact Analysis

Unauthorized users may access sensitive search results from remote managed hubs. This requires the FEATURE_FEDERATED_SEARCH feature to be enabled, which is off by default. If enabled, attackers with valid credentials could view data they shouldn't have access to until the cache expires.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Information disclosure may result in non-compliance with data protection regulations, potentially leading to legal and financial penalties.

Mitigation Strategies

Disable the FEATURE_FEDERATED_SEARCH flag if federated search functionality is not required. This prevents the improper bearer token reuse. If federated search is needed, consider alternative mitigations as disabling the feature will impact functionality. Monitor for unauthorized access attempts and update to a patched version once available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71468. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart