CVE-2026-71470
A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom Resource (CR) editor, to manipulate Search CR fields such as imageOverride, arguments, and environment variables without proper validation. By exploiting this, an attacker can mount arbitrary secrets into a search container's environment or replace the container image with an attacker-controlled one. This leads to privilege escalation and can result in a full cluster compromise due to the ServiceAccount's extensive impersonation permissions.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.42%
- CWE
- CWE-913
- Published
- 2026-08-19
- Last modified
- 2026-09-05
Affected products
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.13
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.15
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.17
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.11
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.14
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.16
Weakness type
Related vulnerabilities
- CVE-2026-41870 — Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)
- CVE-2026-65181 — Apache Impala: RCE via External Data Source Class Loading
- CVE-2026-85408 — Eleveo Quality Management Conversation events dynamically-determined object attributes
- CVE-2026-84430 — gouguoa edit_personal Endpoint Index.php update dynamically-determined object attributes
- CVE-2026-48105 — Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths without validation, enabling cluster-wide path-traversal worm primitive
- CVE-2026-76023 — Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed...
- CVE-2026-47698 — vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
- CVE-2026-73226 — Electerm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/function invocation due to missing method-name allowlist