Sceawere

Vulnerability Detail

CVE-2026-71473UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

search-v2-operator Arbitrary Configuration Injection

Vulnerability Metadata

Severity
High
Score / CVSS
8.5
Creation Date
3h ago
Vendor
Red Hat
Product
Red Hat Advanced Cluster Management for Kubernetes 2
Attack Type
Improperly Controlled Modification of Dynamically-Determined Object Attributes
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to inject arbitrary configuration data. This manipulation can override critical settings, leading to the replacement of container images. This ultimately results in container image injection on the managed cluster, potentially compromising its integrity.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.5",
  "pubDate": "2026-08-12T22:17:16.020Z",
  "pubdate": "2026-08-12T22:17:16.020Z",
  "executiveSummary": "A configuration injection vulnerability has been identified within the search-v2-operator component. This security flaw allows a malicious actor possessing specific administrative permissions on a managed cluster to inject arbitrary configuration data.\nThe successful exploitation of this vulnerability results in the overriding of critical system settings, which subsequently permits the unauthorized replacement of container images.\nUltimately, this enables container image injection on the targeted managed cluster, severely compromising the overall integrity and security posture of the infrastructure.\nThe risk implications include unauthorized code execution and potential persistence within the managed cluster environment.\nRequired conditions for successful exploitation include authenticated access with specific administrative permissions on a managed cluster interacting with the vulnerable search-v2-operator component.",
  "technicalDetails": "The vulnerability resides within the configuration parsing and handling logic of the search-v2-operator component. The root cause stems from insufficient validation and sanitization of input data supplied through administrative interfaces on a managed cluster.\nBecause the component fails to properly restrict or validate configuration parameters, an authenticated user possessing specific administrative permissions can inject arbitrary configuration data into the operational flow.\nThe exploitation method involves crafting and submitting malicious configuration payloads that target critical system parameters managed by the operator.\nDuring the attack flow, the injected configuration data successfully overrides existing critical settings within the search-v2-operator operational context.\nThis manipulation directly targets the underlying container deployment definitions or mapping mechanisms managed by the operator.\nConsequently, the system processes the falsified configuration and proceeds to execute the unauthorized replacement of designated container images with attacker-supplied alternatives.\nAuthentication requirements dictate that the attacker must possess specific administrative permissions on a managed cluster to interact with the vulnerable component's control mechanisms.\nThe post-exploitation impact includes container image injection, leading to potential execution of unauthorized workloads, compromise of cluster integrity, and escalation of privilege within the affected managed cluster."
}
CVE-2026-71473: search-v2-operator Arbitrary Configuration Injection (HIGH Severity, CVSS: 8.5) - Sceawere