CVE-2026-70495

A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If an attacker gains access to any of the pods running under this service account, they could exploit this to achieve `system:masters` access, granting them full control over the cluster.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-17 20:16

Updated : 2026-08-27 04:16


NVD link : CVE-2026-70495

Mitre link : CVE-2026-70495

CVE.ORG link : CVE-2026-70495


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management