PT-2026-76763 · Unknown · Acm-Search-V2-Rhel9
CVE-2026-71472
·
Published
2026-08-17
·
Updated
2026-08-27
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
acm-search-v2-rhel9 (affected versions not specified)
Description
An authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, can inject malicious shell commands or SQL statements. This issue exists because the
WORK MEM string provided in the Search CR is not properly validated before being used in a bash script and an SQL query. Successful exploitation may lead to arbitrary code execution within the privileged postgres pod, potentially compromising the system.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acm-Search-V2-Rhel9