Arbitrary Code Execution Vulnerability in Red Hat ACM Search Product
CVE-2026-71472

9.1CRITICAL

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
17 August 2026

What is CVE-2026-71472?

A vulnerability exists in the ACM Search feature of Red Hat's product, which can be exploited by authenticated users, such as hub administrators or Search Custom Resource editors. This flaw originates from insufficient validation of the WORK_MEM string used in bash scripts and SQL queries, enabling an attacker to inject malicious shell commands or SQL statements. If exploited, this could lead to arbitrary code execution within the privileged PostgreSQL pod, jeopardizing the integrity and security of the system.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.