Sceawere
Vulnerability Detail
CVE-2026-71471UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
acm-search-v2-rhel9 Image Override RCE
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9
- Creation Date
- 3h ago
- Vendor
- Red Hat
- Product
- Red Hat Advanced Cluster Management for Kubernetes 2
- Attack Type
- Inclusion of Functionality from Untrusted Control Sphere
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This allows the attacker to deploy an arbitrary container image across all managed clusters. The consequence is remote code execution (RCE), enabling the attacker to execute commands and potentially access sensitive information across the entire fleet of managed clusters.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.0",
"pubDate": "2026-08-12T22:17:15.890Z",
"pubdate": "2026-08-12T22:17:15.890Z",
"executiveSummary": "A remote code execution vulnerability has been identified in acm-search-v2-rhel9. This security flaw enables an attacker who possesses administrative privileges and patch access to the Search Custom Resource on the hub cluster to manipulate container image deployment specifications. By leveraging the Collector.ImageOverride field improperly, malicious actors can force the deployment of arbitrary container images across all connected managed clusters. The primary impact of this vulnerability encompasses full remote code execution throughout the managed cluster fleet, leading to potential unauthorized command execution and unauthorized access to sensitive operational and application data across the entire multi-cluster infrastructure. Exploitation strictly requires pre-existing administrative privileges and patch access capabilities targeted specifically at the Search Custom Resource within the hub cluster environment, representing a significant escalation vector for compromised administrative accounts.",
"technicalDetails": "The vulnerability resides within the acm-search-v2-rhel9 component, specifically stemming from insufficient validation and improper handling of configuration inputs within the Collector.ImageOverride field. The root cause is centered around the lack of integrity checks and restriction enforcement on image references supplied via the Search Custom Resource on the hub cluster. Authentication requirements dictate that the attacker must already possess administrative privileges on the hub cluster alongside explicit patch access authorization to modify the target Search Custom Resource. Because the hub cluster orchestrates and propagates configurations downward to downstream managed clusters, any payload injected into the configuration parameters is automatically distributed globally. The exploitation flow proceeds as follows: First, the authenticated attacker accesses the hub cluster API and initiates a patch operation targeting the Search Custom Resource. Second, the attacker inserts a malicious or arbitrary container image reference into the Collector.ImageOverride field. Third, the orchestration engine processes this updated Custom Resource and propagates the modified collector deployment manifests to all enrolled managed clusters. Fourth, the managed clusters pull and instantiate the specified arbitrary container image within their respective environments. The payload behavior involves executing malicious code embedded within the unauthorized container image context upon deployment. Post-exploitation impact is severe, granting the adversary remote code execution capabilities across the entire fleet of managed clusters, thereby facilitating lateral movement, cluster-wide compromise, and widespread exposure of sensitive data assets managed within the infrastructure."
}