VYPR

search-v2-operator

by Red Hat

CVEs (3)

  • CVE-2026-70496CriAug 19, 2026
    risk 0.64cvss 9.9epss 0.01

    A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Requests (CSRs), and manage…

  • CVE-2026-71470CriAug 19, 2026
    risk 0.59cvss 9.1epss 0.01

    A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom Resource (CR) editor, to manipulate Search CR fields such as imageOverride, arguments, and environment variables without proper validation. By exploiting this, an…

  • CVE-2026-70495HigAug 17, 2026
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If an attacker gains access to any of the pods running under this service account, they could…