CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-70496

criticalCVSS 9.9covered by 1 sourcefirst seen 2026-08-19
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Requests (CSRs), and manage ManifestWork. This grants excessive privileges beyond what is necessary for the operator's intended function, potentially leading to privilege escalation within the cluster.

⚡ Watch CVE-2026-70496

Get an email if CVE-2026-70496 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-70496

CVE.org record

Embed the live status

CVE-2026-70496 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-70496 status](https://www.csirts.com/badge/CVE-2026-70496)](https://www.csirts.com/cve/CVE-2026-70496)