Executive brief
Red Hat Advanced Cluster Management for Kubernetes contains a configuration injection vulnerability in the search-v2-operator component that allows administrators with specific permissions to manipulate critical cluster settings and replace container images. An attacker exploiting this flaw could compromise the integrity of managed Kubernetes clusters by injecting malicious container images, potentially leading to unauthorized code execution and cluster takeover.
Technical details
A configuration injection vulnerability exists in the search-v2-operator component that allows an authenticated attacker with specific administrative permissions on a managed cluster to inject arbitrary configuration data. The vulnerability permits overriding critical settings, enabling arbitrary container image replacement on the managed cluster. This affects Red Hat Advanced Cluster Management for Kubernetes v2.17.1 and earlier versions. The attack requires elevated administrative privileges on the target managed cluster. A patch is available in the RHSA-2026:60386 security advisory.
Affected products
- Red Hat Advanced Cluster Management for Kubernetes 2.17.1 and earlier
Timeline
- 2026-08-12: disclosed
- 2026-08-26: advisory: RHSA-2026:60386 issued