{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/search-v2-operator/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-71470"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["search-v2-operator"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","cloud-security","kubernetes"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eThe search-v2-operator is susceptible to a privilege escalation vulnerability (CVE-2026-71470) that arises from insufficient validation of fields within Search Custom Resources (CRs). An attacker who already possesses the authorization to edit these CRs can inject malicious configurations into the environment. Specifically, the vulnerability allows for the modification of imageOverride, execution arguments, and environment variables. By leveraging these fields, an attacker can replace the legitimate search container with a malicious image or mount sensitive cluster secrets directly into the container's environment. The risk is significantly amplified because the ServiceAccount associated with the search operator typically maintains extensive permissions within the Kubernetes cluster, potentially enabling full cluster compromise. This issue affects deployments using the search-v2-operator and requires strict RBAC controls for CR editing access as a primary mitigation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for privilege escalation from a CR editor role to cluster-wide impact. By exfiltrating secrets or executing arbitrary code via container replacement, an attacker can move laterally or gain administrative control over the cluster environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestrict access to edit Search Custom Resources (CRs) using Kubernetes Role-Based Access Control (RBAC) to only highly trusted service accounts or users.\u003c/li\u003e\n\u003cli\u003eAudit existing RBAC policies to identify users or service accounts with permissions to edit Search CRs.\u003c/li\u003e\n\u003cli\u003eApply the latest security patches provided by the vendor for the search-v2-operator to remediate the validation flaw (CVE-2026-71470).\u003c/li\u003e\n\u003cli\u003eImplement Admission Controllers to validate the image registry and configuration of newly created or modified containers to prevent unauthorized image deployment.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-19T18:38:14Z","date_published":"2026-08-19T18:38:14Z","id":"https://feed.craftedsignal.io/briefs/2026-08-search-v2-operator-vulnerability/","summary":"A vulnerability in the search-v2-operator allows a privileged user to manipulate Custom Resource fields, leading to secret exfiltration and container image replacement.","title":"Privilege Escalation in search-v2-operator via Arbitrary CR Manipulation","url":"https://feed.craftedsignal.io/briefs/2026-08-search-v2-operator-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Search-V2-Operator","version":"https://jsonfeed.org/version/1.1"}