Red Hat Search-v2-Operator: Arbitrary Config Injection & Container Image Replacement
CVE-2026-71473 Published on August 12, 2026
Acm-search-v2-rhel9: search-v2-operator: addonfactory.getvaluesfromaddonannotation enables arbitrary helm-values override per spoke
A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to inject arbitrary configuration data. This manipulation can override critical settings, leading to the replacement of container images. This ultimately results in container image injection on the managed cluster, potentially compromising its integrity.
Vulnerability Analysis
CVE-2026-71473 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity, and no impact on availability.
Timeline
Reported to Red Hat.
Made public. 6 days later.
Weakness Type
What is a Mass Assignment Vulnerability?
The software receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
CVE-2026-71473 has been classified to as a Mass Assignment vulnerability or weakness.
Products Associated with CVE-2026-71473
Want to know whenever a new CVE is published for Red Hat Acm? stack.watch will email you.