Red HatCVE-2026-70495
Red Hat Advanced Cluster Management: improper privilege management
High8.8CVE-2026-70495 · Published Aug 17, 2026 · updated Aug 27, 2026
A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If an attacker gains access to any of the pods running under this service account, they could exploit this to achieve `system:masters` access, granting them full control over the cluster.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-269
- www.cve.org/CVERecord?id=CVE-2026-70495
- nvd.nist.gov/vuln/detail/CVE-2026-70495
- access.redhat.com/errata/RHSA-2026:60386
- access.redhat.com/errata/RHSA-2026:60387
- access.redhat.com/errata/RHSA-2026:60388
- access.redhat.com/errata/RHSA-2026:60389
- access.redhat.com/errata/RHSA-2026:60390
- access.redhat.com/errata/RHSA-2026:60391
- access.redhat.com/security/cve/CVE-2026-70495
- bugzilla.redhat.com/show_bug.cgi?id=2511031
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 17 | Red Hat managedcluster-import-controller: privilege escalation | Critical9.9 | No fix yet |
| Aug 17 | Red Hat acm-search-v2-rhel9. This vulnerability: code execution | Critical9.1 | No fix yet |
| Aug 17 | Red Hat multicloud-operators-subscription: privilege escalation | Critical9.9 | No fix yet |
| Aug 17 | Red Hat fakefish: missing authentication | Critical9.3 | No fix yet |
| Aug 17 | Red Hat fakefish: command injection | High7.7 | No fix yet |
| Aug 17 | Red Hat OpenShift AI (RHOAI): remote code execution | High7.9 | No fix yet |