{"apiVersion":"1.0","identifier":"CVE-2026-71470","description":"A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom Resource (CR) editor, to manipulate Search CR fields such as imageOverride, arguments, and environment variables without proper validation. By exploiting this, an attacker can mount arbitrary secrets into a search container-s environment or replace the container image with an attacker-controlled one. This leads to privilege escalation and can result in a full cluster compromise due to the ServiceAccount-s extensive impersonation permissions.","publishedAt":"2026-08-19T17:20:57","lastModifiedAt":"2026-08-27T04:16:47","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-71470","cvssScore":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","epssProbability":0.00418,"riskScore":0.94,"affectedProduct":"search-v2-operator","affectedVersions":"unknown","vulnerabilityType":"Other","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-71470","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-71470","en":"https://www.redsauce.net/en/cves/CVE-2026-71470","fr":"https://www.redsauce.net/fr/cves/CVE-2026-71470","pt":"https://www.redsauce.net/pt/cves/CVE-2026-71470","de":"https://www.redsauce.net/de/cves/CVE-2026-71470","sk":"https://www.redsauce.net/sk/cves/CVE-2026-71470","el":"https://www.redsauce.net/el/cves/CVE-2026-71470"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-71470"}}