CVE-2026-71471
A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This allows the attacker to deploy an arbitrary container image across all managed clusters. The consequence is remote code execution (RCE), enabling the attacker to execute commands and potentially access sensitive information across the entire fleet of managed clusters.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
- EPSS probability
- 1.02%
- CWE
- CWE-829
- Published
- 2026-08-12
- Last modified
- 2026-09-07
Affected products
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.13
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.15
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.17
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.11
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.14
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.16
Weakness type
Related vulnerabilities
- CVE-2026-0303 — Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File
- CVE-2026-79721 — Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer,...
- CVE-2026-86504 — In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev...
- CVE-2026-86169 — Axolotl through 0.18.0 Remote Code Execution via Multipack Patching
- CVE-2026-82525 — Exterro FTK Imager < 8.3 XXE via Report.xml XSLT Processing
- CVE-2026-58569 — Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability....
- CVE-2026-18252 — Inclusion of Functionality from Untrusted Control Sphere in GitLab
- CVE-2026-76139 — Acm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/release@master with full build credentials