Privilege Escalation Vulnerability in Search Operator by Red Hat
CVE-2026-71470

9.1CRITICAL

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
19 August 2026

What is CVE-2026-71470?

A flaw exists in the search-v2-operator that enables privileged users, specifically Custom Resource editors, to manipulate Search Custom Resource fields without adequate validation. This manipulation allows attackers to inject arbitrary sensitive information into the environment of search containers or replace the container's image with a malicious version. Such actions can escalate privileges significantly, potentially compromising the entire cluster due to the extensive impersonation permissions associated with ServiceAccounts.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.