PT-2026-78536 · Red Hat · Red Hat Advanced Cluster Management For Kubernetes 2+6
CVE-2026-71470
·
Published
2026-08-19
·
Updated
2026-08-27
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
search-v2-operator (affected versions not specified)
Description
A flaw in the search-v2-operator allows a privileged user with Custom Resource (CR) editor permissions to manipulate Search CR fields without proper validation. The affected fields include
imageOverride, arguments, and environment variables. An attacker can exploit this to mount arbitrary secrets into a search container's environment or replace the container image with one under their control. This leads to privilege escalation and potential full cluster compromise because the ServiceAccount possesses extensive impersonation permissions.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Advanced Cluster Management For Kubernetes 2
Red Hat Advanced Cluster Management For Kubernetes 2.11
Red Hat Advanced Cluster Management For Kubernetes 2.13
Red Hat Advanced Cluster Management For Kubernetes 2.14
Red Hat Advanced Cluster Management For Kubernetes 2.15
Red Hat Advanced Cluster Management For Kubernetes 2.16
Red Hat Advanced Cluster Management For Kubernetes 2.17