MEDIUMVulnerability

CVE-2026-71468

A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access to remote managed hub search results, leading to information disclosure.

Properties

severity
MEDIUM
score
5.3
cve_id
CVE-2026-71468
vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
published_at
2026-08-11T20:18:45.410
last_modified
2026-08-26T23:17:15.857

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Incorrect Privilege Assignment

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-71468 — Ninja Signal Threat Intelligence | Ninja Signal