CVE-2026-71471: Inclusion of Functionality from Untrusted Control Sphere in Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.11
A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This allows the attacker to deploy an arbitrary container image across all managed clusters. The consequence is remote code execution (RCE), enabling the attacker to execute commands and potentially access sensitive information across the entire fleet of managed clusters.
AI Analysis
Technical Summary
A vulnerability exists in the acm-search-v2-rhel9 component of Red Hat Advanced Cluster Management for Kubernetes 2, where a highly privileged user with patch access to the Search Custom Resource (CR) on the hub cluster can manipulate the Collector.ImageOverride field. This manipulation allows deployment of arbitrary container images to all managed clusters, resulting in remote code execution and possible secret exfiltration across the entire managed fleet. The vulnerability is due to the inclusion of functionality from an untrusted control sphere, specifically the propagation of the Collector.ImageOverride field. The CVSS v3.1 base score is 9.0 (critical) with network attack vector, low complexity, high privileges required, no user interaction, changed scope, and high confidentiality and integrity impact with low availability impact. The vendor advisory recommends restricting patch access to the Search CR to trusted administrators as a mitigation. No patch or official fix status is currently provided in the advisory.
Potential Impact
An attacker with administrative privileges and patch access to the Search CR on the hub cluster can execute arbitrary container images across all managed clusters, enabling remote code execution and potential access to sensitive information fleet-wide. This compromises confidentiality, integrity, and availability to a high degree, with the ability to execute unauthorized code and exfiltrate secrets across the managed Kubernetes clusters.
Mitigation Recommendations
The vendor advisory states that to mitigate this vulnerability, patch access to the Search Custom Resource (CR) should be restricted exclusively to trusted and authorized hub administrators. This limits the ability of unauthorized users to modify the Collector.ImageOverride field and deploy arbitrary container images. No official patch or fix has been confirmed yet; therefore, organizations should apply this access restriction as an immediate mitigation and monitor the vendor advisory for updates on patch availability.
CVE-2026-71471: Inclusion of Functionality from Untrusted Control Sphere in Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.11
Description
A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This allows the attacker to deploy an arbitrary container image across all managed clusters. The consequence is remote code execution (RCE), enabling the attacker to execute commands and potentially access sensitive information across the entire fleet of managed clusters.
CVSS v3.1
Score 9.0critical
Affected software
Red Hat
Red Hat Advanced Cluster Management for Kubernetes 2.11
Red Hat
Red Hat Advanced Cluster Management for Kubernetes 2.13
Red Hat
Red Hat Advanced Cluster Management for Kubernetes 2.14
Red Hat
Red Hat Advanced Cluster Management for Kubernetes 2.15
Red Hat
Red Hat Advanced Cluster Management for Kubernetes 2.16
Red Hat
Red Hat Advanced Cluster Management for Kubernetes 2.17
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A vulnerability exists in the acm-search-v2-rhel9 component of Red Hat Advanced Cluster Management for Kubernetes 2, where a highly privileged user with patch access to the Search Custom Resource (CR) on the hub cluster can manipulate the Collector.ImageOverride field. This manipulation allows deployment of arbitrary container images to all managed clusters, resulting in remote code execution and possible secret exfiltration across the entire managed fleet. The vulnerability is due to the inclusion of functionality from an untrusted control sphere, specifically the propagation of the Collector.ImageOverride field. The CVSS v3.1 base score is 9.0 (critical) with network attack vector, low complexity, high privileges required, no user interaction, changed scope, and high confidentiality and integrity impact with low availability impact. The vendor advisory recommends restricting patch access to the Search CR to trusted administrators as a mitigation. No patch or official fix status is currently provided in the advisory.
Potential Impact
An attacker with administrative privileges and patch access to the Search CR on the hub cluster can execute arbitrary container images across all managed clusters, enabling remote code execution and potential access to sensitive information fleet-wide. This compromises confidentiality, integrity, and availability to a high degree, with the ability to execute unauthorized code and exfiltrate secrets across the managed Kubernetes clusters.
Mitigation Recommendations
The vendor advisory states that to mitigate this vulnerability, patch access to the Search Custom Resource (CR) should be restricted exclusively to trusted and authorized hub administrators. This limits the ability of unauthorized users to modify the Collector.ImageOverride field and deploy arbitrary container images. No official patch or fix has been confirmed yet; therefore, organizations should apply this access restriction as an immediate mitigation and monitor the vendor advisory for updates on patch availability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-08-06T19:34:07.970Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-71471","vendor":"Red Hat"}]
Threat ID: 6a7cefadbf8831d5393cbeb4
Added to database: 08/12/2026, 22:11:57 UTC
Last enriched: 08/12/2026, 22:26:17 UTC
Last updated: 09/25/2026, 13:47:48 UTC
Views: 68
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.