Bug 2512152 (CVE-2026-71473)

Summary: CVE-2026-71473 acm-search-v2-rhel9: CVE-2026-71473 search-v2-operator: addonfactory.GetValuesFromAddonAnnotation enables arbitrary Helm-values override per spoke
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: gparvin, rhaigner, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to inject arbitrary configuration data. This manipulation can override critical settings, leading to the replacement of container images. This ultimately results in container image injection on the managed cluster, potentially compromising its integrity.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-06 19:35:57 UTC
addon-framework's GetValuesFromAddonAnnotation reads the addon.open-cluster-management.io/values annotation on a ManagedClusterAddOn and deep-merges arbitrary JSON into the Helm values. Because it is listed after getValue, it can override global.imageOverrides.search_collector, org, fullnameOverride, etc. A user with patch managedclusteraddons permission in a single managed-cluster namespace can replace the collector image for that spoke without touching the hub Search CR, achieving container image injection on the managed cluster.

Upstream: stolostron/search-v2-operator