What is CVE-2026-70496?
CVE-2026-70496: A flaw in search-v2-operator grants its ClusterRole cluster administrator privileges, enabling impersonation, RBAC manipulation, CSR approval, and ManifestWork management. Affected deployments should update the operator immediately and audit RBAC permissions.
Azərbaycanca: CVE-2026-70496: search-v2-operator-da aşkar olunmuş bu qüsur, operatorun ClusterRole-unun cluster administrator imtiyazlarına malik olması səbəbindən digər obyektləri təqlid etmək, RBAC konfiqurasiyalarını dəyişdirmək, CSR-ları təsdiqləmək və ManifestWork-i idarə etmək kimi icazəsiz əməliyyatlara yol açır. Təsirə məruz qalan qurğular dərhal operatoru yeniləməli və RBAC icazələrini audit etməlidir.
Related CVEs
link basis: same weakness class CWE-269
FAQ1
What unauthorized operations can search-v2-operator perform due to CVE-2026-70496?
Due to this flaw, search-v2-operator can perform unauthorized operations such as impersonating other objects, manipulating RBAC configurations, approving CSRs, and managing ManifestWork.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.