Bug 2512149 (CVE-2026-71470) - CVE-2026-71470 acm-search-v2-rhel9: CVE-2026-71470 search-v2-operator: Search CR imageOverride/arguments/envVar flow unsanitized into pods running impersonating SA
Summary: CVE-2026-71470 acm-search-v2-rhel9: CVE-2026-71470 search-v2-operator: Search...
Keywords:
Status: NEW
Alias: CVE-2026-71470
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-06 19:35 UTC by OSIDB Bzimport
Modified: 2026-08-19 15:54 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-06 19:35:26 UTC
The search-v2-operator applies Search CR fields (imageOverride, arguments, envVar) directly to pod specs without allow-list, registry pinning, digest enforcement, or argument validation. The Env field supports valueFrom.secretKeyRef, allowing a CR editor to mount any secret in the namespace into a search container's environment, or replace the image with an attacker-controlled one. The landing pod's ServiceAccount holds cluster-wide impersonate on users/groups/serviceaccounts (FIND-001), escalating image injection to full cluster compromise.

No allow-list, registry pinning, digest enforcement, or argument validation is performed. Same class as KeplerInternal / numaresources image-override findings.

Upstream: stolostron/search-v2-operator


Note You need to log in before you can comment on or make changes to this bug.