Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
To mitigate this issue, ensure that the `FEATURE_FEDERATED_SEARCH` is not enabled if federated search functionality is not required. This feature is disabled by default in Red Hat Advanced Cluster Management for Kubernetes. If `FEATURE_FEDERATED_SEARCH` is enabled, consider disabling it to prevent unauthorized cross-user data access. Disabling this feature will impact the ability to perform federated searches across managed hubs.
Thu, 13 Aug 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat advanced Cluster Management For Kubernetes
|
|
| Vendors & Products |
Redhat advanced Cluster Management For Kubernetes
|
Wed, 12 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 11 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access to remote managed hub search results, leading to information disclosure. | |
| Title | Acm-search-v2-api-rhel9: search-v2-api: cross-user bearer-token reuse via global federation-config cache | |
| First Time appeared |
Redhat
Redhat acm |
|
| Weaknesses | CWE-266 | |
| CPEs | cpe:/a:redhat:acm:2 | |
| Vendors & Products |
Redhat
Redhat acm |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-12T16:58:07.313Z
Reserved: 2026-08-06T19:34:07.969Z
Link: CVE-2026-71468
Updated: 2026-08-12T16:04:26.714Z
Status : Received
Published: 2026-08-11T20:18:45.410
Modified: 2026-08-12T17:17:31.483
Link: CVE-2026-71468
OpenCVE Enrichment
Updated: 2026-08-13T10:30:04Z