THREAT OPS › Threat News › [NVD] CVE-2026-76827 (MEDIUM 6.8) — A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELET
[NVD] CVE-2026-76827 (MEDIUM 6.8) — A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELET
CVE-2026-76827 CVSS: 6.8 MEDIUM Published: 2026-08-19T21:17:39.227
A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the calling cluster. A
Indicators of compromise
- CVE-2026-76827cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-76827