Security Advisory

CVE-2026-71468

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-11 19:24:21
Last updated 2026-08-11 19:24:21
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access to remote managed hub search results, leading to information disclosure.