---
id: CVE-2026-71471
title: >-
  Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride
  propagated to every spoke as arbitrary container image
summary: >-
  A flaw was found in acm-search-v2-rhel9. An attacker with administrative
  privileges on the hub cluster, specifically with patch access to the Search
  Custom Resource (CR), could exploit a vulnerability in the
  `Collector.ImageOverride` fie…
severity: critical
cvss: 9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L'
cvssSource: cna
cwe:
  - CWE-829
vendor: Red Hat
product: rhacm2/acm-search-v2-rhel9
affected:
  - rhacm2/acm-search-v2-rhel9 (all versions)
  - rhacm2/acm-search-v2-rhel9 (all versions)
  - rhacm2/acm-search-v2-rhel9 (all versions)
  - rhacm2/acm-search-v2-rhel9 (all versions)
  - rhacm2/acm-search-v2-rhel9 (all versions)
  - rhacm2/acm-search-v2-rhel9 (all versions)
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-13T13:07:05.772119Z'
published: '2026-08-12'
updated: '2026-09-07'
sourceUpdated: '2026-09-07T18:39:51.276Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-71471'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:60386'
    label: 'RHSA-2026:60386'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60387'
    label: 'RHSA-2026:60387'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60388'
    label: 'RHSA-2026:60388'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60389'
    label: 'RHSA-2026:60389'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60390'
    label: 'RHSA-2026:60390'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60391'
    label: 'RHSA-2026:60391'
  - url: 'https://access.redhat.com/security/cve/CVE-2026-71471'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2512150'
    label: RHBZ#2512150
tags:
  - cve.org
epss: 0.01022
epssPercentile: 0.61951
ingestedAt: '2026-09-08T15:33:27.004Z'
---

## Overview

A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This allows the attacker to deploy an arbitrary container image across all managed clusters. The consequence is remote code execution (RCE), enabling the attacker to execute commands and potentially access sensitive information across the entire fleet of managed clusters.

## Affected

- `rhacm2/acm-search-v2-rhel9 (all versions)`
- `rhacm2/acm-search-v2-rhel9 (all versions)`
- `rhacm2/acm-search-v2-rhel9 (all versions)`
- `rhacm2/acm-search-v2-rhel9 (all versions)`
- `rhacm2/acm-search-v2-rhel9 (all versions)`
- `rhacm2/acm-search-v2-rhel9 (all versions)`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

### Workarounds

To mitigate this issue, restrict patch access to the Search Custom Resource (CR) to only trusted and authorized hub administrators. This limits the ability of unauthorized principals to modify the `Collector.ImageOverride` field and deploy arbitrary container images across the managed fleet.
