Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-70496: Search-v2-operator has excessive cluster administrator permissions

CVE-2026-70496 · published 4 days ago
Summary

The Search-v2-operator has too many permissions, which could allow an attacker to take control of the cluster. This is a concern because the operator is meant to manage search functionality, not have full control over the cluster. To mitigate this, update the operator to limit its permissions to what is necessary for its intended function.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
red hat red hat advanced cluster management for kubernetes 2 All versions
Original advisory text
Search-v2-operator: search-v2-operator: operator clusterrole is cluster-admin equivalent via impersonate, rbac write, csr approve, and manifestwork
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Requests (CSRs), and manage ManifestWork. This grants excessive privileges beyond what is necessary for the operator's intended function, potentially leading to privilege escalation within the cluster.
Severity
9.9 Critical
CVSS 3.1: 9.9 (NVD)
Exploitation
EPSS <1%
Type
CWE-250
Timeline
Published19 Aug 2026
Updated20 Aug 2026
First seen19 Aug 2026
Sources
CVE-2026-70496 · MITRE
Monitor software like this
Free during beta