Red HatCVE-2026-70496
Red Hat Advanced Cluster Management for Kubernetes 2: improper access control
Critical9.9CVE-2026-70496 · Published Aug 19, 2026 · updated Aug 27, 2026
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Requests (CSRs), and manage ManifestWork. This grants excessive privileges beyond what is necessary for the operator's intended function, potentially leading to privilege escalation within the cluster.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-250
- www.cve.org/CVERecord?id=CVE-2026-70496
- nvd.nist.gov/vuln/detail/CVE-2026-70496
- access.redhat.com/errata/RHSA-2026:60386
- access.redhat.com/errata/RHSA-2026:60387
- access.redhat.com/errata/RHSA-2026:60388
- access.redhat.com/errata/RHSA-2026:60389
- access.redhat.com/errata/RHSA-2026:60390
- access.redhat.com/errata/RHSA-2026:60391
- access.redhat.com/security/cve/CVE-2026-70496
- bugzilla.redhat.com/show_bug.cgi?id=2511032
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 19 | Red Hat search-indexer. This vulnerability: protection mechanism failure | Medium6.8 | No fix yet |
| Aug 19 | Red Hat acm-operator-bundle. The build process: untrusted functionality included | High8.0 | No fix yet |
| Aug 19 | Red Hat mce-operator-bundle. The build process fetches: remote code execution | High7.7 | No fix yet |
| Aug 19 | Red Hat: authentication bypass | Critical9.3 | No fix yet |
| Aug 19 | Red Hat volsync-addon-controller. This vulnerability: code injection | Medium6.2 | No fix yet |
| Aug 19 | Red Hat search-v2-operator. This vulnerability: privilege escalation | Critical9.1 | No fix yet |