Junglewise Threat Intelligence

CVE-2026-71472: Red Hat Advanced Cluster Management command injection in Search CR

CVE-2026-71472 · Severity: critical · CVSS 9.1 · Published 2026-08-17

Vendors: Red Hat.

Executive brief

Red Hat Advanced Cluster Management for Kubernetes is a platform that manages multiple Kubernetes clusters from a central console. A flaw in the Search component allows authenticated administrators or custom resource editors to inject malicious shell commands and SQL statements through insufficiently validated configuration parameters, potentially leading to arbitrary code execution with database privileges and full system compromise.

Technical details

The vulnerability is a command injection and SQL injection flaw in acm-search-v2-rhel9. The WORK_MEM string provided in the Search Custom Resource (CR) is not properly validated before being used in a bash script and an SQL query. An authenticated attacker (such as a hub administrator or Search CR editor) can inject malicious payloads through this field. Successful exploitation results in arbitrary code execution within the privileged postgres pod, compromising the database and potentially the entire system. The attack requires authentication and direct access to create or edit Search CR objects. A patch is available via Red Hat Advisory RHSA-2026:60386.

Affected products

  • Red Hat Advanced Cluster Management for Kubernetes 2.17.0 and earlier

Timeline

  • 2026-08-17: disclosed
  • 2026-08-26: advisory: Red Hat Security Advisory RHSA-2026:60386 issued
  • 2026-08-26: patched: Fix available via RHSA-2026:60386

References