{"apiVersion":"1.0","identifier":"CVE-2026-76827","description":"A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster-s indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the calling cluster. An attacker could exploit this by crafting specific user identifiers (UIDs) with a different cluster-s prefix.","publishedAt":"2026-08-19T21:17:39","lastModifiedAt":"2026-08-27T04:16:49","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76827","cvssScore":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N","epssProbability":0.00316,"riskScore":0.7,"affectedProduct":"search-indexer","affectedVersions":"unknown","vulnerabilityType":"Other","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-76827","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-76827","en":"https://www.redsauce.net/en/cves/CVE-2026-76827","fr":"https://www.redsauce.net/fr/cves/CVE-2026-76827","pt":"https://www.redsauce.net/pt/cves/CVE-2026-76827","de":"https://www.redsauce.net/de/cves/CVE-2026-76827","sk":"https://www.redsauce.net/sk/cves/CVE-2026-76827","el":"https://www.redsauce.net/el/cves/CVE-2026-76827"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-76827"}}