Skip to content
Red HatCVE-2026-71472

Red Hat acm-search-v2-rhel9. This vulnerability: code execution

Critical9.1CVE-2026-71472 · Published Aug 17, 2026 · updated Aug 27, 2026

A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or SQL statements. This occurs because the WORK_MEM string provided in the Search CR is not properly validated before being used in a bash script and an SQL query. Successful exploitation could lead to arbitrary code execution within the privileged postgres pod, potentially compromising the system.

Red Hat advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat managedcluster-import-controller: privilege escalation
Critical9.9Aug 17
Red Hat Advanced Cluster Management: improper privilege management
High8.8Aug 17
Red Hat multicloud-operators-subscription: privilege escalation
Critical9.9Aug 17
Red Hat fakefish: missing authentication
Critical9.3Aug 17
Red Hat fakefish: command injection
High7.7Aug 17
Red Hat OpenShift AI (RHOAI): remote code execution
High7.9Aug 17

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.