Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-71470— Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow unsanitized into pods running impersonating sa

Quick assessment

Affected
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.13
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 search-v2-operator 中发现了一个漏洞。该漏洞允许具有特权的用户(具体为自定义资源(CR)编辑器)在未经验证的情况下操纵搜索 CR 字段,例如 imageOverride、参数和环境变量。通过利用此漏洞,攻击者可以将任意秘密挂载到搜索容器的环境中,或用攻击者控制的镜像替换容器镜像。这会导致权限提升,并可能由于 ServiceAccount 具有广泛的 impersonation(模拟)权限,从而导致整个集群被完全入侵。

CVSS 9.1 · Critical EPSS 0.33% · P25

Affected Version Matrix 1

VendorProduct Version RangeStatus
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2 any affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-71470

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow unsanitized into pods running impersonating sa
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom Resource (CR) editor, to manipulate Search CR fields such as imageOverride, arguments, and environment variables without proper validation. By exploiting this, an attacker can mount arbitrary secrets into a search container's environment or replace the container image with an attacker-controlled one. This leads to privilege escalation and can result in a full cluster compromise due to the ServiceAccount's extensive impersonation permissions.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
动态管理代码资源的控制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.13 1787682112 ~ * cpe:/a:redhat:acm:2.13::el9
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.15 1787681674 ~ * cpe:/a:redhat:acm:2.15::el9
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.17 1787681651 ~ * cpe:/a:redhat:acm:2.17::el9

II. Public POCs for CVE-2026-71470

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-71470

登录查看更多情报信息。

Vendor Advisories for CVE-2026-71470 (2)

Other References for CVE-2026-71470 (3)

Same Patch Batch · Red Hat · 2026-08-19 · 10 CVEs total

CVE-2026-70496 9.9 CRITICAL Search-v2-operator: search-v2-operator: operator clusterrole is cluster-admin equivalent v
CVE-2026-66794 9.3 CRITICAL Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluste
CVE-2026-76139 8.0 HIGH Acm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/release@m
CVE-2026-75569 7.7 HIGH Mce-operator-bundle: mce-operator-bundle: bundle-generation business logic fetched from mu
CVE-2026-76235 7.5 HIGH Cockpit-ws: cockpit: cockpit-ws: unauthenticated remote memory leak via cockpitlang cookie
CVE-2026-76827 6.8 MEDIUM Search-indexer: search-indexer: update/delete operations not scoped to caller's cluster (c
CVE-2026-18874 6.2 MEDIUM Volsync-addon-controller: volsync-addon-controller: annotation values rendered into yaml v
CVE-2026-75900 6.1 MEDIUM Swtpm: swtpm: out-of-bounds read in swtpm_nvram_checkheader due to sizeof(pointer) vs size
CVE-2026-76166 4.3 MEDIUM Modcluster-core: mod_cluster advertise listener: unauthenticated dos via crafted multicast

IV. Related Vulnerabilities

V. Comments for CVE-2026-71470

No comments yet


Leave a comment