PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-70495 Red Hat CVE debrief

The CVE-2026-70495 record indicates a flaw in the search-v2-operator component's `search-serviceaccount`, which has overly broad permissions. This allows impersonation of users and groups across the entire cluster if an attacker gains access to any pod running under this service account. The vulnerability class is related to improper permission management in Kubernetes components. Likely operational impact includes potential for attackers to achieve `system:masters` access, granting them full control over the cluster. Source-confidence limits are based on official CVE and NVD information. Review context suggests immediate verification and restriction of `search-serviceaccount` permissions.

Vendor
Red Hat
Product
Red Hat Advanced Cluster Management for Kubernetes 2.11
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-17
Original CVE updated
2026-08-27
Advisory published
2026-08-17
Advisory updated
2026-08-27

Who should care

Organizations using the search-v2-operator component, particularly those with cluster-admin or equivalent access, should be aware of this vulnerability and take immediate action to verify and restrict the permissions of the `search-serviceaccount` service account.

Technical summary

The search-v2-operator component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If an attacker gains access to any of the pods running under this service account, they could exploit this to achieve `system:masters` access, granting them full control over the cluster. The vulnerability is particularly concerning in environments where cluster-admin or equivalent access is present. Defensive impact includes the need for immediate verification and restriction of service account permissions, as well as ensuring pods running under this service account are properly secured and monitored. Official references include Red Hat errata RHSA-2026:60386, RHSA-2026:60387, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60390, and RHSA-2026:60391, along with a bugzilla entry for further details on affected scope and vendor guidance. Affected product context indicates that organizations using the search-v2-operator component should prioritize these actions to mitigate potential exposure. The CVSS score of 8.8 with a HIGH severity underscores the critical nature of this vulnerability. Technical framing emphasizes the importance of restricting service account permissions and securing pods to prevent exploitation. Source-grounded information supports the urgency of applying defensive measures without delay. Additional technical details can be found in the official CVE record and NVD vulnerability assessment, which provide further insights into the vulnerability's characteristics and potential impact. It is essential to review these sources for comprehensive understanding and to guide remediation efforts effectively. The CVE record was published on 2026-08-17T20:16:45.653Z and has not been modified since then, indicating that the information provided is current and relevant to the vulnerability's status as of that date. This context supports the need for prompt action to address the vulnerability and minimize potential risks to cluster security and integrity. The search-v2-operator component, being a critical part of cluster management, requires immediate attention to prevent potential misuse by attackers. By

Defensive priority

Organizations using the search-v2-operator component should prioritize verifying and restricting the permissions of the `search-serviceaccount` service account, and ensure that pods running under this service account are properly secured.

Recommended defensive actions

  • Verify and restrict the permissions of the `search-serviceaccount` service account
  • Ensure pods running under this service account are properly secured and monitored
  • Review and apply Red Hat errata RHSA-2026:60386, RHSA-2026:60387, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60390, and RHSA-2026:60391
  • Investigate and address potential exposure of pods to unauthorized access
  • Perform a thorough review of cluster-admin or equivalent access to ensure it is properly secured
  • Implement monitoring and detection for pods running under the `search-serviceaccount` service account
  • Review and update asset inventory to reflect the current status of the search-v2-operator component

Evidence notes

The CVE-2026-70495 record indicates a flaw in the search-v2-operator component's `search-serviceaccount`, which has overly broad permissions. This allows impersonation of users and groups across the entire cluster if an attacker gains access to any pod running under this service account. The CVSS score is 8.8 with a HIGH severity. Official references include Red Hat errata and a bugzilla entry.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-70495 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-70495

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-70495 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-70495

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.