Executive brief
A vulnerability in Red Hat's search-v2-operator component allows a user with Custom Resource editing permissions to manipulate container configurations without validation. An attacker can inject malicious environment variables, mount unauthorized secrets, or replace the container image entirely, leading to full cluster compromise. This is particularly dangerous because the underlying ServiceAccount has extensive permissions to impersonate other identities across the Kubernetes cluster.
Technical details
The search-v2-operator fails to properly validate user input when modifying Search Custom Resource (CR) fields including imageOverride, arguments, and environment variables. A CR editor—a privileged but not cluster-admin role—can exploit this to mount arbitrary secrets into search containers or replace the container image with an attacker-controlled variant. The underlying ServiceAccount's broad impersonation permissions amplify the impact, enabling attackers to escalate privileges and potentially compromise the entire cluster. The vulnerability is network-reachable to any user with CR editing permissions and requires no additional authentication or user interaction beyond the existing privilege level.
Affected products
- Red Hat Advanced Cluster Management for Kubernetes 2.17.x
Timeline
- 2026-08-19: disclosed
- 2026-08-26: advisory