Privilege Escalation Vulnerability in Search Operator by Red Hat
CVE-2026-71470
9.1CRITICAL
What is CVE-2026-71470?
A flaw exists in the search-v2-operator that enables privileged users, specifically Custom Resource editors, to manipulate Search Custom Resource fields without adequate validation. This manipulation allows attackers to inject arbitrary sensitive information into the environment of search containers or replace the container's image with a malicious version. Such actions can escalate privileges significantly, potentially compromising the entire cluster due to the extensive impersonation permissions associated with ServiceAccounts.