Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this vulnerability, ensure the `FEATURE_FEDERATED_SEARCH` is disabled if not actively used. This feature is off by default in standard deployments of Red Hat Advanced Cluster Management for Kubernetes. For Global Hub deployments where `FEATURE_FEDERATED_SEARCH` is enabled by default, consider restricting network access to the `search-v2-api`'s `/federated` endpoint to trusted clients.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includes an `Upgrade: websocket` header. An unauthenticated attacker can exploit this by sending a specially crafted HTTP POST request to the `/federated` endpoint with the `Upgrade: websocket` header. This allows the attacker to bypass authentication and access federated search results across all configured remote managed hubs, leading to information disclosure. | |
| Title | Acm-search-v2-api-rhel9: search-v2-api: authentication bypass on /federated via upgrade: websocket header spoofing | |
| First Time appeared |
Redhat
Redhat acm |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:/a:redhat:acm:2 | |
| Vendors & Products |
Redhat
Redhat acm |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-11T20:08:51.599Z
Reserved: 2026-08-06T19:34:07.969Z
Link: CVE-2026-71467
No data.
Status : Received
Published: 2026-08-11T20:18:45.260
Modified: 2026-08-11T20:18:45.260
Link: CVE-2026-71467
No data.
OpenCVE Enrichment
No data.