Arbitrary Code Execution Vulnerability in Red Hat ACM Search Product
CVE-2026-71472
9.1CRITICAL
What is CVE-2026-71472?
A vulnerability exists in the ACM Search feature of Red Hat's product, which can be exploited by authenticated users, such as hub administrators or Search Custom Resource editors. This flaw originates from insufficient validation of the WORK_MEM string used in bash scripts and SQL queries, enabling an attacker to inject malicious shell commands or SQL statements. If exploited, this could lead to arbitrary code execution within the privileged PostgreSQL pod, jeopardizing the integrity and security of the system.