PatchSiren cyber security CVE debrief
CVE-2026-70495 Red Hat CVE debrief
The CVE-2026-70495 record indicates a flaw in the search-v2-operator component's `search-serviceaccount`, which has overly broad permissions. This allows impersonation of users and groups across the entire cluster if an attacker gains access to any pod running under this service account. The vulnerability class is related to improper permission management in Kubernetes components. Likely operational impact includes potential for attackers to achieve `system:masters` access, granting them full control over the cluster. Source-confidence limits are based on official CVE and NVD information. Review context suggests immediate verification and restriction of `search-serviceaccount` permissions.
- Vendor
- Red Hat
- Product
- Red Hat Advanced Cluster Management for Kubernetes 2.11
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-17
- Original CVE updated
- 2026-08-27
- Advisory published
- 2026-08-17
- Advisory updated
- 2026-08-27
Who should care
Organizations using the search-v2-operator component, particularly those with cluster-admin or equivalent access, should be aware of this vulnerability and take immediate action to verify and restrict the permissions of the `search-serviceaccount` service account.
Technical summary
The search-v2-operator component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If an attacker gains access to any of the pods running under this service account, they could exploit this to achieve `system:masters` access, granting them full control over the cluster. The vulnerability is particularly concerning in environments where cluster-admin or equivalent access is present. Defensive impact includes the need for immediate verification and restriction of service account permissions, as well as ensuring pods running under this service account are properly secured and monitored. Official references include Red Hat errata RHSA-2026:60386, RHSA-2026:60387, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60390, and RHSA-2026:60391, along with a bugzilla entry for further details on affected scope and vendor guidance. Affected product context indicates that organizations using the search-v2-operator component should prioritize these actions to mitigate potential exposure. The CVSS score of 8.8 with a HIGH severity underscores the critical nature of this vulnerability. Technical framing emphasizes the importance of restricting service account permissions and securing pods to prevent exploitation. Source-grounded information supports the urgency of applying defensive measures without delay. Additional technical details can be found in the official CVE record and NVD vulnerability assessment, which provide further insights into the vulnerability's characteristics and potential impact. It is essential to review these sources for comprehensive understanding and to guide remediation efforts effectively. The CVE record was published on 2026-08-17T20:16:45.653Z and has not been modified since then, indicating that the information provided is current and relevant to the vulnerability's status as of that date. This context supports the need for prompt action to address the vulnerability and minimize potential risks to cluster security and integrity. The search-v2-operator component, being a critical part of cluster management, requires immediate attention to prevent potential misuse by attackers. By
Defensive priority
Organizations using the search-v2-operator component should prioritize verifying and restricting the permissions of the `search-serviceaccount` service account, and ensure that pods running under this service account are properly secured.
Recommended defensive actions
- Verify and restrict the permissions of the `search-serviceaccount` service account
- Ensure pods running under this service account are properly secured and monitored
- Review and apply Red Hat errata RHSA-2026:60386, RHSA-2026:60387, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60390, and RHSA-2026:60391
- Investigate and address potential exposure of pods to unauthorized access
- Perform a thorough review of cluster-admin or equivalent access to ensure it is properly secured
- Implement monitoring and detection for pods running under the `search-serviceaccount` service account
- Review and update asset inventory to reflect the current status of the search-v2-operator component
Evidence notes
The CVE-2026-70495 record indicates a flaw in the search-v2-operator component's `search-serviceaccount`, which has overly broad permissions. This allows impersonation of users and groups across the entire cluster if an attacker gains access to any pod running under this service account. The CVSS score is 8.8 with a HIGH severity. Official references include Red Hat errata and a bugzilla entry.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-70495 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-70495
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-70495 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-70495
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60386
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60387
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60388
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60389
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60390
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60391
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-70495
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.