Bug 2512147 (CVE-2026-71468)

Summary: CVE-2026-71468 acm-search-v2-api-rhel9: CVE-2026-71468 search-v2-api: Cross-user bearer-token reuse via global federation-config cache
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: gparvin, rhaigner, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access to remote managed hub search results, leading to information disclosure.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-06 19:35:04 UTC
cachedFedConfig is a package-level singleton with no per-user keying (fedConfig.go:35). When getFederationConfig refreshes the cache, it captures the current request's bearer token and reuses it for all subsequent federated requests until the cache TTL expires. This means the first user to trigger a cache miss after TTL expiry donates their token to all subsequent federated queries by other users, enabling cross-user data access to remote managed hub search results.

Precondition: FEATURE_FEDERATED_SEARCH=true (default off; enabled for Global Hub deployments) and at least one remote managed hub configured with a search-global ManagedServiceAccount Secret.

Upstream: stolostron/search-v2-api