High severity7.5NVD Advisory· Published Aug 11, 2026· Updated Aug 11, 2026
CVE-2026-71467
CVE-2026-71467
Description
A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includes an Upgrade: websocket header. An unauthenticated attacker can exploit this by sending a specially crafted HTTP POST request to the /federated endpoint with the Upgrade: websocket header. This allows the attacker to bypass authentication and access federated search results across all configured remote managed hubs, leading to information disclosure.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.