PT-2026-76763 · Unknown · Acm-Search-V2-Rhel9

CVE-2026-71472

·

Published

2026-08-17

·

Updated

2026-08-27

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions acm-search-v2-rhel9 (affected versions not specified)
Description An authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, can inject malicious shell commands or SQL statements. This issue exists because the WORK MEM string provided in the Search CR is not properly validated before being used in a bash script and an SQL query. Successful exploitation may lead to arbitrary code execution within the privileged postgres pod, potentially compromising the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71472

Affected Products

Acm-Search-V2-Rhel9