Red Hat search-v2-operator. This vulnerability: privilege escalation
Critical9.1CVE-2026-71470 · Published Aug 19, 2026 · updated Aug 27, 2026
A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom Resource (CR) editor, to manipulate Search CR fields such as imageOverride, arguments, and environment variables without proper validation. By exploiting this, an attacker can mount arbitrary secrets into a search container's environment or replace the container image with an attacker-controlled one. This leads to privilege escalation and can result in a full cluster compromise due to the ServiceAccount's extensive impersonation permissions.
Affected versions
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-913
- www.cve.org/CVERecord?id=CVE-2026-71470
- nvd.nist.gov/vuln/detail/CVE-2026-71470
- access.redhat.com/errata/RHSA-2026:60386
- access.redhat.com/errata/RHSA-2026:60387
- access.redhat.com/errata/RHSA-2026:60388
- access.redhat.com/errata/RHSA-2026:60389
- access.redhat.com/errata/RHSA-2026:60390
- access.redhat.com/errata/RHSA-2026:60391
- access.redhat.com/security/cve/CVE-2026-71470
- bugzilla.redhat.com/show_bug.cgi?id=2512149
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 19 | Red Hat search-indexer. This vulnerability: protection mechanism failure | Medium6.8 | No fix yet |
| Aug 19 | Red Hat acm-operator-bundle. The build process: untrusted functionality included | High8.0 | No fix yet |
| Aug 19 | Red Hat mce-operator-bundle. The build process fetches: remote code execution | High7.7 | No fix yet |
| Aug 19 | Red Hat Advanced Cluster Management for Kubernetes 2: improper access control | Critical9.9 | No fix yet |
| Aug 19 | Red Hat: authentication bypass | Critical9.3 | No fix yet |
| Aug 19 | Red Hat volsync-addon-controller. This vulnerability: code injection | Medium6.2 | No fix yet |