<Vulnerability name="CVE-2026-70496">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-08-19T15:00:00</PublicDate>
    <Bugzilla id="2511032" url="https://bugzilla.redhat.com/show_bug.cgi?id=2511032" xml:lang="en:us">
search-v2-operator: search-v2-operator: operator ClusterRole is cluster-admin equivalent via impersonate, RBAC write, CSR approve, and ManifestWork
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>9.9</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-250</CWE>
    <Details xml:lang="en:us" source="Mitre">
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Requests (CSRs), and manage ManifestWork. This grants excessive privileges beyond what is necessary for the operator's intended function, potentially leading to privilege escalation within the cluster.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Requests (CSRs), and manage ManifestWork. This grants excessive privileges beyond what is necessary for the operator's intended function, potentially leading to privilege escalation within the cluster.
    </Details>
    <Statement xml:lang="en:us">
This is an Important flaw in Red Hat Advanced Cluster Management for Kubernetes where the search-v2-operator ClusterRole possesses privileges equivalent to cluster-admin. This excessive permission set, including impersonation, RBAC write, CSR signer-approve, and ManifestWork spoke fan-out, allows the operator to perform actions beyond its intended scope, posing a security risk to the cluster. Exploitation requires an attacker to already hold low-privileged access (PR:L), which is why this does not meet the bar for Critical under the unauthenticated-RCE standard.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.11::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.11</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60387">RHSA-2026:60387</Advisory>
        <Package name="rhacm2/acm-search-v2-rhel9">rhacm2/acm-search-v2-rhel9:1787688827</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.13::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.13</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60390">RHSA-2026:60390</Advisory>
        <Package name="rhacm2/acm-search-v2-rhel9">rhacm2/acm-search-v2-rhel9:1787682112</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.14::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.14</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60388">RHSA-2026:60388</Advisory>
        <Package name="rhacm2/acm-search-v2-rhel9">rhacm2/acm-search-v2-rhel9:1787682033</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.15::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.15</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60389">RHSA-2026:60389</Advisory>
        <Package name="rhacm2/acm-search-v2-rhel9">rhacm2/acm-search-v2-rhel9:1787681674</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.16::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.16</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60391">RHSA-2026:60391</Advisory>
        <Package name="rhacm2/acm-search-v2-rhel9">rhacm2/acm-search-v2-rhel9:1787681686</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.17::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.17</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60386">RHSA-2026:60386</Advisory>
        <Package name="rhacm2/acm-search-v2-rhel9">rhacm2/acm-search-v2-rhel9:1787681651</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.17::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.17</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60386">RHSA-2026:60386</Advisory>
        <Package name="rhacm2/search-collector-rhel9">rhacm2/search-collector-rhel9:1787229539</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/a:redhat:acm:2">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhacm2/multiclusterhub-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-70496
https://nvd.nist.gov/vuln/detail/CVE-2026-70496
    </References>
</Vulnerability>