← Back to CVE search

CVE-2026-71473

search-v2-operator

Description

A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to inject arbitrary configuration data. This manipulation can override critical settings, leading to the replacement of container images. This ultimately results in container image injection on the managed cluster, potentially compromising its integrity.

CVSS 8.5EPSS 0.347%Risk 0.88
View source
Published
2026-08-12 22:17:16
Affected versions
unknown
Type
Docker image
Last modified
2026-08-27 04:16:47
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N