A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access to remote managed hub search results, leading to information disclosure.
History

Wed, 12 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access to remote managed hub search results, leading to information disclosure.
Title Acm-search-v2-api-rhel9: search-v2-api: cross-user bearer-token reuse via global federation-config cache
First Time appeared Redhat
Redhat acm
Weaknesses CWE-266
CPEs cpe:/a:redhat:acm:2
Vendors & Products Redhat
Redhat acm
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-12T16:58:07.313Z

Reserved: 2026-08-06T19:34:07.969Z

Link: CVE-2026-71468

cve-icon Vulnrichment

Updated: 2026-08-12T16:04:26.714Z

cve-icon NVD

Status : Received

Published: 2026-08-11T20:18:45.410

Modified: 2026-08-12T17:17:31.483

Link: CVE-2026-71468

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-11T12:00:00Z

Links: CVE-2026-71468 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T19:45:08Z