LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-71471

Published
CVSS9
Severitycritical
WeaknessCWE-829
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L

Description

A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This allows the attacker to deploy an arbitrary container image across all managed clusters. The consequence is remote code execution (RCE), enabling the attacker to execute commands and potentially access sensitive information across the entire fleet of managed clusters.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-71471

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-71471.