Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

A flaw was found in the search-v2-operator component. (CVE-2026-71473)

0
High
Published: 08/13/2026 (08/13/2026, 00:31:26 UTC)
Source: GCVE Database

Description

CVE-2026-71473 is a high-severity vulnerability in the search-v2-operator component of Red Hat Advanced Cluster Management for Kubernetes. It allows a user with specific administrative permissions on a managed cluster to inject arbitrary configuration data by manipulating Helm values. This can lead to container image injection, privilege escalation, and arbitrary code execution on the managed cluster, compromising its integrity. Currently, no effective mitigation or official fix meeting Red Hat's criteria is available.

CVSS v3.1

Score 8.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 00:56:37 UTC

Technical Analysis

This vulnerability (CVE-2026-71473) affects the search-v2-operator component in Red Hat Advanced Cluster Management for Kubernetes. An attacker with patch managedclusteraddons permission can exploit the flaw by manipulating the addon.open-cluster-management.io/values annotation on a ManagedClusterAddOn resource. This enables arbitrary override of Helm values, resulting in container image injection and privilege escalation on the managed cluster. The flaw is categorized under CWE-915 (Improperly Controlled Modification of Dynamically-Determined Object Attributes). The CVSS 3.1 base score is 8.5 (high), with network attack vector, low complexity, low privileges required, no user interaction, and scope changed. Confidentiality impact is high, integrity impact is low, and availability impact is none. Red Hat has not provided an official fix or mitigation that meets their criteria for ease of use, applicability, or stability.

Potential Impact

An attacker with specific administrative permissions can inject arbitrary container images into the managed cluster by overriding critical configuration settings. This leads to container image injection, privilege escalation, and arbitrary code execution on the managed cluster, potentially compromising its integrity and confidentiality. The vulnerability does not impact availability. There are no known exploits in the wild at this time.

Mitigation Recommendations

Currently, Red Hat has not released an official fix or mitigation that meets their criteria for ease of use, applicability, or stability. Users should monitor Red Hat advisories for updates. Until a fix is available, restricting administrative permissions on managed clusters and monitoring for unauthorized configuration changes may reduce risk, but no direct mitigation is provided by Red Hat.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-mm7v-f498-mqrj
Osv Schema Version
1.4.0
Aliases
["CVE-2026-71473"]
Ecosystems
[]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6a7d12d0bf8831d5396c174a

Added to database: 08/13/2026, 00:41:52 UTC

Last enriched: 08/13/2026, 00:56:37 UTC

Last updated: 08/13/2026, 02:41:00 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses