Privilege Escalation Vulnerability in Search Operator by Red Hat
CVE-2026-71470
9.1CRITICAL
Key Information:
What is CVE-2026-71470?
A flaw exists in the search-v2-operator that enables privileged users, specifically Custom Resource editors, to manipulate Search Custom Resource fields without adequate validation. This manipulation allows attackers to inject arbitrary sensitive information into the environment of search containers or replace the container's image with a malicious version. Such actions can escalate privileges significantly, potentially compromising the entire cluster due to the extensive impersonation permissions associated with ServiceAccounts.
Affected Version(s)
Red Hat Advanced Cluster Management for Kubernetes 2.11 1787688827
Red Hat Advanced Cluster Management for Kubernetes 2.13 1787682112
Red Hat Advanced Cluster Management for Kubernetes 2.14 1787682033