A flaw was found in the search-v2-operator component. (CVE-2026-71473)
CVE-2026-71473 is a high-severity vulnerability in the search-v2-operator component of Red Hat Advanced Cluster Management for Kubernetes. It allows a user with specific administrative permissions on a managed cluster to inject arbitrary configuration data by manipulating Helm values. This can lead to container image injection, privilege escalation, and arbitrary code execution on the managed cluster, compromising its integrity. Currently, no effective mitigation or official fix meeting Red Hat's criteria is available.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-71473) affects the search-v2-operator component in Red Hat Advanced Cluster Management for Kubernetes. An attacker with patch managedclusteraddons permission can exploit the flaw by manipulating the addon.open-cluster-management.io/values annotation on a ManagedClusterAddOn resource. This enables arbitrary override of Helm values, resulting in container image injection and privilege escalation on the managed cluster. The flaw is categorized under CWE-915 (Improperly Controlled Modification of Dynamically-Determined Object Attributes). The CVSS 3.1 base score is 8.5 (high), with network attack vector, low complexity, low privileges required, no user interaction, and scope changed. Confidentiality impact is high, integrity impact is low, and availability impact is none. Red Hat has not provided an official fix or mitigation that meets their criteria for ease of use, applicability, or stability.
Potential Impact
An attacker with specific administrative permissions can inject arbitrary container images into the managed cluster by overriding critical configuration settings. This leads to container image injection, privilege escalation, and arbitrary code execution on the managed cluster, potentially compromising its integrity and confidentiality. The vulnerability does not impact availability. There are no known exploits in the wild at this time.
Mitigation Recommendations
Currently, Red Hat has not released an official fix or mitigation that meets their criteria for ease of use, applicability, or stability. Users should monitor Red Hat advisories for updates. Until a fix is available, restricting administrative permissions on managed clusters and monitoring for unauthorized configuration changes may reduce risk, but no direct mitigation is provided by Red Hat.
A flaw was found in the search-v2-operator component. (CVE-2026-71473)
Description
CVE-2026-71473 is a high-severity vulnerability in the search-v2-operator component of Red Hat Advanced Cluster Management for Kubernetes. It allows a user with specific administrative permissions on a managed cluster to inject arbitrary configuration data by manipulating Helm values. This can lead to container image injection, privilege escalation, and arbitrary code execution on the managed cluster, compromising its integrity. Currently, no effective mitigation or official fix meeting Red Hat's criteria is available.
CVSS v3.1
Score 8.5high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-71473) affects the search-v2-operator component in Red Hat Advanced Cluster Management for Kubernetes. An attacker with patch managedclusteraddons permission can exploit the flaw by manipulating the addon.open-cluster-management.io/values annotation on a ManagedClusterAddOn resource. This enables arbitrary override of Helm values, resulting in container image injection and privilege escalation on the managed cluster. The flaw is categorized under CWE-915 (Improperly Controlled Modification of Dynamically-Determined Object Attributes). The CVSS 3.1 base score is 8.5 (high), with network attack vector, low complexity, low privileges required, no user interaction, and scope changed. Confidentiality impact is high, integrity impact is low, and availability impact is none. Red Hat has not provided an official fix or mitigation that meets their criteria for ease of use, applicability, or stability.
Potential Impact
An attacker with specific administrative permissions can inject arbitrary container images into the managed cluster by overriding critical configuration settings. This leads to container image injection, privilege escalation, and arbitrary code execution on the managed cluster, potentially compromising its integrity and confidentiality. The vulnerability does not impact availability. There are no known exploits in the wild at this time.
Mitigation Recommendations
Currently, Red Hat has not released an official fix or mitigation that meets their criteria for ease of use, applicability, or stability. Users should monitor Red Hat advisories for updates. Until a fix is available, restricting administrative permissions on managed clusters and monitoring for unauthorized configuration changes may reduce risk, but no direct mitigation is provided by Red Hat.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-mm7v-f498-mqrj
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-71473"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a7d12d0bf8831d5396c174a
Added to database: 08/13/2026, 00:41:52 UTC
Last enriched: 08/13/2026, 00:56:37 UTC
Last updated: 08/13/2026, 02:41:00 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.