Bug 2511032 (CVE-2026-70496)

Summary: CVE-2026-70496 search-v2-operator: search-v2-operator: operator ClusterRole is cluster-admin equivalent via impersonate, RBAC write, CSR approve, and ManifestWork
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: gparvin, rhaigner, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Requests (CSRs), and manage ManifestWork. This grants excessive privileges beyond what is necessary for the operator's intended function, potentially leading to privilege escalation within the cluster.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-04 15:11:34 UTC
A flaw was found in search-v2-operator (stolostron/search-v2-operator). The operator ClusterRole is cluster-admin equivalent via impersonate + RBAC write + CSR signer-approve + ManifestWork spoke fan-out, granting excessive privileges beyond what is required for the operator's function.

Upstream Jira: ACM-34432