Red HatCVE-2026-71472
Red Hat acm-search-v2-rhel9. This vulnerability: code execution
Critical9.1CVE-2026-71472 · Published Aug 17, 2026 · updated Aug 27, 2026
A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or SQL statements. This occurs because the WORK_MEM string provided in the Search CR is not properly validated before being used in a bash script and an SQL query. Successful exploitation could lead to arbitrary code execution within the privileged postgres pod, potentially compromising the system.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
- www.cve.org/CVERecord?id=CVE-2026-71472
- nvd.nist.gov/vuln/detail/CVE-2026-71472
- access.redhat.com/errata/RHSA-2026:60386
- access.redhat.com/errata/RHSA-2026:60387
- access.redhat.com/errata/RHSA-2026:60388
- access.redhat.com/errata/RHSA-2026:60389
- access.redhat.com/errata/RHSA-2026:60390
- access.redhat.com/errata/RHSA-2026:60391
- access.redhat.com/security/cve/CVE-2026-71472
- bugzilla.redhat.com/show_bug.cgi?id=2512151
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 17 | Red Hat managedcluster-import-controller: privilege escalation | Critical9.9 | No fix yet |
| Aug 17 | Red Hat Advanced Cluster Management: improper privilege management | High8.8 | No fix yet |
| Aug 17 | Red Hat multicloud-operators-subscription: privilege escalation | Critical9.9 | No fix yet |
| Aug 17 | Red Hat fakefish: missing authentication | Critical9.3 | No fix yet |
| Aug 17 | Red Hat fakefish: command injection | High7.7 | No fix yet |
| Aug 17 | Red Hat OpenShift AI (RHOAI): remote code execution | High7.9 | No fix yet |