Bug 2519896 (CVE-2026-76827) - CVE-2026-76827 search-indexer: search-indexer: UPDATE/DELETE operations not scoped to caller's cluster (cross-tenant data tampering)
Summary: CVE-2026-76827 search-indexer: search-indexer: UPDATE/DELETE operations not s...
Keywords:
Status: NEW
Alias: CVE-2026-76827
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-19 19:59 UTC by OSIDB Bzimport
Modified: 2026-08-19 20:03 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-19 19:59:01 UTC
Delta-sync write paths in search-indexer do not constrain UPDATE/DELETE mutations to rows owned by the authenticated cluster. UIDs are conventionally <clusterName>/<k8s-uid> by collector convention, but the indexer never enforces this prefix. A registered managed cluster can submit a payload with a victim cluster's UID in updateResources or deleteResources and mutate/delete that cluster's indexed data, even when posting to its own /clusters/<self>/sync path. The INSERT path's ON CONFLICT (uid) DO UPDATE also overwrites an existing row's data regardless of which cluster owns it, since the cluster column is not part of the conflict target or re-checked.

This is a defense-in-depth failure independent of authentication/identity-binding gaps tracked separately -- exploiting it requires already being a legitimately registered, authenticated managed spoke cluster with valid addon-framework credentials, not an anonymous or low-privilege caller.

Upstream Jira: ACM-42544


Note You need to log in before you can comment on or make changes to this bug.