A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access to remote managed hub search results, leading to information disclosure.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 11 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access to remote managed hub search results, leading to information disclosure. | |
| Title | Acm-search-v2-api-rhel9: search-v2-api: cross-user bearer-token reuse via global federation-config cache | |
| First Time appeared |
Redhat
Redhat acm |
|
| Weaknesses | CWE-266 | |
| CPEs | cpe:/a:redhat:acm:2 | |
| Vendors & Products |
Redhat
Redhat acm |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-12T16:58:07.313Z
Reserved: 2026-08-06T19:34:07.969Z
Link: CVE-2026-71468
Updated: 2026-08-12T16:04:26.714Z
Status : Received
Published: 2026-08-11T20:18:45.410
Modified: 2026-08-12T17:17:31.483
Link: CVE-2026-71468
OpenCVE Enrichment
Updated: 2026-08-12T19:45:08Z