Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-76827
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.11 — Search-indexer: search-indexer: update/delete operations not scoped to caller's cluster (cross-tenant data tampering)
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L H N C N H N 6.8 .0053 42.5 —
AFFECTED
Product Versions Fixed
Red Hat Advanced Cluster Management for Kubernetes 2.11 unspecified 1787688957
Red Hat Advanced Cluster Management for Kubernetes 2.13 unspecified 1787262474
Red Hat Advanced Cluster Management for Kubernetes 2.14 unspecified 1787250074
Red Hat Advanced Cluster Management for Kubernetes 2.15 unspecified 1787249293
Red Hat Advanced Cluster Management for Kubernetes 2.16 unspecified 1787248491
Red Hat Advanced Cluster Management for Kubernetes 2.17 unspecified 1787247085
TIMELINE
Aug 19 Reserved by redhat
Aug 19 Published (CNA: redhat)
Aug 26 PATCH SHIPPED — CVE-2026-76827 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787688957.
Description
A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the calling cluster. An attacker could exploit this by crafting specific user identifiers (UIDs) with a different cluster's prefix.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| August 19, 2026 | Reserved | Reserved by redhat |
| August 19, 2026 | Published | Published (CNA: redhat) |
| August 26, 2026 | PATCH SHIPPED | PATCH SHIPPED — CVE-2026-76827 (Red Hat Advanced Cluster Management for Kubernetes 2.11). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.11 1787688957. |
Affected
Affected products and packages — 6 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.11 | — | — | 1787688957 |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.13 | — | — | 1787262474 |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.14 | — | — | 1787250074 |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.15 | — | — | 1787249293 |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.16 | — | — | 1787248491 |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.17 | — | — | 1787247085 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-76827 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.