Junglewise Threat Intelligence

CVE-2026-71471: Red Hat Advanced Cluster Management for Kubernetes privilege escalation in Search Custom Resource

CVE-2026-71471 · Severity: critical · CVSS 9 · Published 2026-08-12

Vendors: Red Hat.

Executive brief

Red Hat Advanced Cluster Management for Kubernetes is a platform that manages multiple Kubernetes clusters from a central console. A vulnerability in the Search component allows hub cluster administrators with patch access to deploy arbitrary container images across all managed clusters, enabling remote code execution. An attacker could execute commands and access sensitive information across the entire fleet of managed clusters.

Technical details

The vulnerability exists in the acm-search-v2 component and affects the `Collector.ImageOverride` field in the Search Custom Resource (CR). An authenticated attacker with administrative privileges and patch access to the Search CR can manipulate this field to inject an arbitrary container image, bypassing intended restrictions. This allows deployment of attacker-controlled container images across all managed clusters in the environment, leading to remote code execution. The vulnerability requires administrative access and patch privileges on the hub cluster. A patch is available in Red Hat Advanced Cluster Management for Kubernetes 2.17.1 and later.

Affected products

  • Red Hat Advanced Cluster Management for Kubernetes before 2.17.1

Timeline

  • 2026-08-12: disclosed: CVE published
  • 2026-08-26: advisory: Red Hat security advisory RHSA-2026:60386 issued
  • 2026-08-26: patched: Fix available in ACM 2.17.1

References