{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/acm-search-v2-rhel9/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9,"id":"CVE-2026-71471"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["acm-search-v2-rhel9"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2026-71471 identifies a high-severity vulnerability within the acm-search-v2-rhel9 component of Red Hat Advanced Cluster Management (RHACM). The flaw originates in the handling of the Collector.ImageOverride field within the Search Custom Resource (CR). An attacker who has already obtained administrative privileges on the hub cluster and possesses patch-level access to the Search CR can manipulate this field to point to unauthorized container images.\u003c/p\u003e\n\u003cp\u003eWhen the Search CR is updated with a malicious override, the hub cluster propagates this configuration to all connected managed clusters. The managed clusters then pull and execute the attacker-controlled image. This mechanism enables a persistent remote code execution (RCE) state across the entire managed fleet, effectively bypassing standard image security controls. This is particularly dangerous as it turns a hub-level administrative compromise into a platform-wide breach, facilitating large-scale command execution and potential exfiltration of data across the containerized environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for complete remote code execution on all managed clusters within the RHACM environment. An attacker can use this access to run unauthorized commands with container-level privileges, access environment variables, mount persistent volumes, or pivot into internal networks connected to the managed clusters. Given that RHACM is typically used for fleet management, the scope of impact encompasses the entire managed infrastructure, potentially exposing sensitive data across multiple production nodes.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePerform an audit of administrative access to the hub cluster, ensuring that RBAC policies for patching the Search Custom Resource are strictly limited to necessary service accounts or security administrators.\u003c/li\u003e\n\u003cli\u003eMonitor Kubernetes API server logs for modifications to the Search CR, specifically looking for alterations to the Collector.ImageOverride field.\u003c/li\u003e\n\u003cli\u003eApply the latest security updates provided by Red Hat to patch the acm-search-v2-rhel9 component.\u003c/li\u003e\n\u003cli\u003eImplement image provenance controls (e.g., ImagePolicyWebhook or admission controllers) on managed clusters to restrict the registries or image paths allowed for deployment, mitigating the ability of this specific exploit to pull unauthorized images.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-12T22:51:51Z","date_published":"2026-08-12T22:51:51Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-71471/","summary":"An administrative user on the Red Hat Advanced Cluster Management hub can exploit a flaw in the Collector.ImageOverride field to deploy arbitrary container images and achieve remote code execution across managed clusters.","title":"Remote Code Execution via Search Custom Resource in Red Hat Advanced Cluster Management","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-71471/"}],"language":"en","title":"CraftedSignal Threat Feed - Acm-Search-V2-Rhel9","version":"https://jsonfeed.org/version/1.1"}