Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this issue, ensure that the `FEATURE_FEDERATED_SEARCH` is not enabled if federated search functionality is not required. This feature is disabled by default in Red Hat Advanced Cluster Management for Kubernetes. If `FEATURE_FEDERATED_SEARCH` is enabled, consider disabling it to prevent unauthorized cross-user data access. Disabling this feature will impact the ability to perform federated searches across managed hubs.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access to remote managed hub search results, leading to information disclosure. | |
| Title | Acm-search-v2-api-rhel9: search-v2-api: cross-user bearer-token reuse via global federation-config cache | |
| First Time appeared |
Redhat
Redhat acm |
|
| Weaknesses | CWE-266 | |
| CPEs | cpe:/a:redhat:acm:2 | |
| Vendors & Products |
Redhat
Redhat acm |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-11T19:24:21.036Z
Reserved: 2026-08-06T19:34:07.969Z
Link: CVE-2026-71468
No data.
Status : Received
Published: 2026-08-11T20:18:45.410
Modified: 2026-08-11T20:18:45.410
Link: CVE-2026-71468
No data.
OpenCVE Enrichment
No data.