Bug 2511031 (CVE-2026-70495)

Summary: CVE-2026-70495 search-v2-operator: search-v2-operator: cluster-wide impersonate on users/groups shared across 4 pods grants hub system:masters
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: gparvin, rhaigner, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If an attacker gains access to any of the pods running under this service account, they could exploit this to achieve `system:masters` access, granting them full control over the cluster.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-04 15:11:32 UTC
A flaw was found in search-v2-operator (stolostron/search-v2-operator). The search-serviceaccount is granted cluster-wide impersonate on users/groups/serviceaccounts; all four pods including PostgreSQL run under it — any foothold in any of these pods grants hub system:masters access.

Upstream Jira: ACM-34431

Comment 1 Christopher Lusk 2026-08-04 17:07:35 UTC
Impact downgraded from Critical to Important to align with Aegis CVSS score of 8.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). The impersonate privilege requires local pod access as a prerequisite — an attacker needs an existing foothold in one of the four pods running under search-serviceaccount before escalating to hub system:masters. This local access requirement (AV:L) and low-privileged starting position (PR:L) place the finding squarely in the Important range per Red Hat severity guidelines.