<Vulnerability name="CVE-2026-70495">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-08-17T19:10:00</PublicDate>
    <Bugzilla id="2511031" url="https://bugzilla.redhat.com/show_bug.cgi?id=2511031" xml:lang="en:us">
search-v2-operator: search-v2-operator: cluster-wide impersonate on users/groups shared across 4 pods grants hub system:masters
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>8.8</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-269</CWE>
    <Details xml:lang="en:us" source="Mitre">
A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If an attacker gains access to any of the pods running under this service account, they could exploit this to achieve `system:masters` access, granting them full control over the cluster.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If an attacker gains access to any of the pods running under this service account, they could exploit this to achieve `system:masters` access, granting them full control over the cluster.
    </Details>
    <Statement xml:lang="en:us">
Critical: This flaw in search-v2-operator allows an attacker who gains a foothold in any of the four pods running under the `search-serviceaccount` to achieve cluster-wide `system:masters` privileges. This escalation of privilege poses a severe risk to the integrity and control of the Red Hat Advanced Cluster Management for Kubernetes environment.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.11::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.11</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60387">RHSA-2026:60387</Advisory>
        <Package name="rhacm2/acm-search-v2-rhel9">rhacm2/acm-search-v2-rhel9:1787688827</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.13::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.13</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60390">RHSA-2026:60390</Advisory>
        <Package name="rhacm2/acm-search-v2-rhel9">rhacm2/acm-search-v2-rhel9:1787682112</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.14::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.14</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60388">RHSA-2026:60388</Advisory>
        <Package name="rhacm2/acm-search-v2-rhel9">rhacm2/acm-search-v2-rhel9:1787682033</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.15::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.15</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60389">RHSA-2026:60389</Advisory>
        <Package name="rhacm2/acm-search-v2-rhel9">rhacm2/acm-search-v2-rhel9:1787681674</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.16::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.16</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60391">RHSA-2026:60391</Advisory>
        <Package name="rhacm2/acm-search-v2-rhel9">rhacm2/acm-search-v2-rhel9:1787681686</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.17::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.17</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60386">RHSA-2026:60386</Advisory>
        <Package name="rhacm2/acm-search-v2-rhel9">rhacm2/acm-search-v2-rhel9:1787681651</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/a:redhat:acm:2">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhacm2/search-collector-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-70495
https://nvd.nist.gov/vuln/detail/CVE-2026-70495
    </References>
</Vulnerability>