Remote Code Execution Vulnerability in ACM Search Component by Red Hat
CVE-2026-71471

9CRITICAL

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
12 August 2026

What is CVE-2026-71471?

A security flaw has been identified in the ACM Search component of Red Hat's offerings. Specifically, an attacker with administrative privileges on the hub cluster, holding patch access to the Search Custom Resource (CR), can exploit this vulnerability in the Collector.ImageOverride field. This issue facilitates the deployment of arbitrary container images across all managed clusters. The resultant effect is the potential for remote code execution (RCE), enabling attackers to execute commands and gain unauthorized access to sensitive information across their entire fleet of managed clusters.

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.