SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-70496

CRITICAL · CVSS 9.9 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A critical vulnerability exists in the search-v2-operator, which has been granted ClusterRole permissions equivalent to a cluster administrator. This excessive privilege allows the operator to impersonate other entities, modify Role-Based Access Control (RBAC) settings, approve Certificate Signing Requests (CSRs), and manage ManifestWork, potentially enabling privilege escalation within the cluster. Organizations utilizing this operator should prioritize immediate remediation to mitigate the risk of unauthorized access and control over their Kubernetes environments.

CVE
CVE-2026-70496
Severity
CRITICAL
CVSS
9.9
EPSS
0.43%

Original NVD Description

A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Requests (CSRs), and manage ManifestWork. This grants excessive privileges beyond what is necessary for the operator's intended function, potentially leading to privilege escalation within the cluster.