{
  "threat_severity" : "Important",
  "public_date" : "2026-08-17T19:10:00Z",
  "bugzilla" : {
    "description" : "search-v2-operator: search-v2-operator: cluster-wide impersonate on users/groups shared across 4 pods grants hub system:masters",
    "id" : "2511031",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2511031"
  },
  "cvss3" : {
    "cvss3_base_score" : "8.8",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
    "status" : "draft"
  },
  "cwe" : "CWE-269",
  "details" : [ "A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If an attacker gains access to any of the pods running under this service account, they could exploit this to achieve `system:masters` access, granting them full control over the cluster." ],
  "statement" : "Critical: This flaw in search-v2-operator allows an attacker who gains a foothold in any of the four pods running under the `search-serviceaccount` to achieve cluster-wide `system:masters` privileges. This escalation of privilege poses a severe risk to the integrity and control of the Red Hat Advanced Cluster Management for Kubernetes environment.",
  "package_state" : [ {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Affected",
    "package_name" : "rhacm2/acm-search-v2-rhel9",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Affected",
    "package_name" : "rhacm2/search-collector-rhel9",
    "cpe" : "cpe:/a:redhat:acm:2"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-70495\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-70495" ],
  "name" : "CVE-2026-70495",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}