What is CVE-2026-70495?
A flaw was found in search-v2-operator where the `search-serviceaccount` has overly broad permissions, enabling it to impersonate users and groups across the entire cluster. If an attacker gains access to any pod running under this service account, they could exploit this for privilege escalation. Immediate auditing of pods using this account and restriction of its permissions is strongly recommended.
Azərbaycanca: search-v2-operator komponentində `search-serviceaccount`-in həddindən artıq geniş icazələrə malik olması səbəbindən imtiyaz yüksəltmə zəifliyi aşkar edilib. Bu, həmin xidmət hesabı altında işləyən istənilən pod-a giriş əldə edən hücumçuya bütün cluster daxilində istifadəçi və qrupları impersonate etməyə imkan verir. Bu xidmət hesabından istifadə edən pod-ların təcili olaraq audit edilməsi və icazələrin məhdudlaşdırılması tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-269
FAQ1
What does the CVE-2026-70495 vulnerability in the search-v2-operator allow an attacker to do?
It allows an attacker who gains access to any pod running under the `search-serviceaccount` to impersonate users and groups across the entire cluster for privilege escalation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.