Bug 2512151 (CVE-2026-71472)

Summary: CVE-2026-71472 acm-search-v2-rhel9: CVE-2026-71472 search-v2-operator: Shell-command and SQL injection in postgresql-start.sh via CR-supplied WORK_MEM
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: gparvin, rhaigner, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or SQL statements. This occurs because the WORK_MEM string provided in the Search CR is not properly validated before being used in a bash script and an SQL query. Successful exploitation could lead to arbitrary code execution within the privileged postgres pod, potentially compromising the system.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-06 19:35:47 UTC
Untrusted Search CR string (WORK_MEM) is concatenated into (a) a bash script line and (b) an SQL literal, with no quoting or validation. The script is mounted at /opt/app-root/src/postgresql-start/postgresql-start.sh (create_pgdeployment.go:50-52) and executed by the sclorg postgres entrypoint inside the postgres pod, which auto-mounts search-serviceaccount with cluster-wide impersonate privileges (FIND-001, FIND-010). A hub admin or Search CR editor can inject arbitrary shell commands or SQL statements executed in the context of the privileged postgres pod.

Upstream: stolostron/search-v2-operator