What is CVE-2026-71471?
A vulnerability in acm-search-v2-rhel9 allows an attacker with administrative privileges on the hub cluster and patch access to the Search Custom Resource to exploit the Collector.ImageOverride field, leading to the deployment of an arbitrary container. If your environment uses this component, it is recommended to apply security updates and restrict administrative access.
Azərbaycanca: acm-search-v2-rhel9 komponentində aşkar edilmiş bu boşluq, hub cluster-də inzibati hüquqlara malik təcavüzkarın Search Custom Resource-a patch girişi vasitəsilə Collector.ImageOverride sahəsini sui-istifadə edərək ixtiyari konteyner yerləşdirməsinə imkan verir. Mühitinizdə bu komponent istifadə olunursa, təhlükəsizlik yeniləmələrini tətbiq etmək və inzibati girişləri məhdudlaşdırmaq tövsiyə olunur.
FAQ2
What level of access does an attacker need to exploit CVE-2026-71471?
The attacker must have administrative privileges on the hub cluster and patch access to the Search Custom Resource.
What mitigation measures are recommended for CVE-2026-71471?
If the acm-search-v2-rhel9 component is in use, it is recommended to apply security updates and restrict administrative access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.