CVE-2026-71467

A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includes an `Upgrade: websocket` header. An unauthenticated attacker can exploit this by sending a specially crafted HTTP POST request to the `/federated` endpoint with the `Upgrade: websocket` header. This allows the attacker to bypass authentication and access federated search results across all configured remote managed hubs, leading to information disclosure.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-11 20:18

Updated : 2026-08-26 22:16


NVD link : CVE-2026-71467

Mitre link : CVE-2026-71467

CVE.ORG link : CVE-2026-71467


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication