THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-76827 (MEDIUM 6.8) — A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELET

[NVD] CVE-2026-76827 (MEDIUM 6.8) — A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELET

mednvdPublished 2026-08-19

CVE-2026-76827 CVSS: 6.8 MEDIUM Published: 2026-08-19T21:17:39.227

A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the calling cluster. A

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-76827