CVE-2026-71472
9.1Red Hat · Red Hat Advanced Cluster Management for Kubernetes 2
An input validation flaw in the acm-search-v2-rhel9 component allows authenticated attackers to perform OS command or SQL injection, potentially leading to arbitrary code execution.
Executive summary
This critical vulnerability in Red Hat Advanced Cluster Management for Kubernetes 2 permits authenticated attackers to execute arbitrary commands or SQL queries, risking full system compromise.
Vulnerability
The vulnerability exists in the acm-search-v2-rhel9 component, which fails to sanitize the WORK_MEM string within Search Custom Resources. An authenticated attacker can inject malicious shell commands or SQL statements that are executed by the privileged postgres pod.
Business impact
Assigned a CVSS score of 9.1, this command and SQL injection vulnerability is highly dangerous. By gaining code execution within the privileged postgres pod, an attacker can manipulate sensitive data, escalate privileges further, or disrupt the operation of the entire management cluster.
Remediation
Immediate Action: Update Red Hat Advanced Cluster Management for Kubernetes 2 to the latest version as recommended by the vendor.
Proactive Monitoring: Monitor database query logs and shell execution logs on the postgres pod for unusual syntax or unauthorized command patterns.
Compensating Controls: Restrict access to the Search Custom Resource creation permissions to only the most trusted administrative users until the patch is applied.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability necessitates immediate remediation. Security teams must ensure that all instances of Red Hat Advanced Cluster Management for Kubernetes 2 are updated to the current secure version to prevent unauthorized code execution and data compromise.