What is CVE-2026-71472?
A vulnerability in Red Hat Advanced Cluster Management's Search component (acm-search-v2-rhel9) allows authenticated attackers, such as hub administrators or Search CR editors, to inject malicious shell commands or SQL statements via the improperly sanitized WORK_MEM parameter passed through the Search Custom Resource. Immediate patching and restriction of Search CR privileges are strongly advised.
Azərbaycanca: Red Hat Advanced Cluster Management (ACM) Search komponentində (acm-search-v2-rhel9) aşkar edilmiş boşluq autentifikasiya olunmuş hücumçuya (hub administratoru və ya Search CR redaktoru) Search Custom Resource vasitəsilə ötürülən WORK_MEM parametrindəki düzgün yoxlanılmamış daxiletmə səbəbindən shell əmrləri və ya SQL ifadələri yeritməyə imkan verir. Sistem administratorları dərhal vendor tərəfindən təqdim edilən təhlükəsizlik yeniləməsini tətbiq etməli və Search CR yaratma/redaktə hüquqlarını məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which component in my Red Hat ACM setup is affected by CVE-2026-71472?
This vulnerability resides in the Search component (acm-search-v2-rhel9) of Red Hat Advanced Cluster Management.
What privileges does an attacker need to exploit this vulnerability?
The attacker must be an authenticated user, specifically a hub administrator or a user with permissions to create or edit the Search Custom Resource.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.