目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-71471— Red Hat acm-search-v2-api 软件供应链问题漏洞

CVSS 9.0 · Critical EPSS 1.45% · P71

Affected Version Matrix 1

ベンダープロダクトVersion Rangeステータス
Red HatRed Hat Advanced Cluster Management for Kubernetes 2anyaffected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-71471の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagated to every spoke as arbitrary container image
ソース: CVE Program / CVE List V5
脆弱性説明
A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This allows the attacker to deploy an arbitrary container image across all managed clusters. The consequence is remote code execution (RCE), enabling the attacker to execute commands and potentially access sensitive information across the entire fleet of managed clusters.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
ソース: CVE Program / CVE List V5
脆弱性タイプ
从非可信控制范围包含功能例程
ソース: CVE Program / CVE List V5
脆弱性タイトル
Red Hat acm-search-v2-api 软件供应链问题漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Red Hat acm-search-v2-api是美国Red Hat公司的一个提供搜索服务的应用程序编程接口。 Red Hat acm-search-v2-api存在软件供应链问题漏洞,该漏洞源于Collector.ImageOverride字段存在缺陷,具有管理员权限的攻击者可能利用该漏洞部署任意容器镜像,导致远程代码执行并可能访问敏感信息。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
Red HatRed Hat Advanced Cluster Management for Kubernetes 2-cpe:/a:redhat:acm:2

II. CVE-2026-71471の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-71471のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-71471 厂商安全公告 (2)

Same Patch Batch · Red Hat · 2026-08-12 · 19 CVEs total

CVE-2026-732689.9 CRITICALCluster-curator-controller: cluster-curator-controller: spec.install.overridejob allows ar
CVE-2026-725269.9 CRITICALMulticloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant
CVE-2026-732699.9 CRITICALCluster-curator-controller: cluster-curator-controller: tenant-controllable trigger create
CVE-2026-725089.9 CRITICALMulticloud-operators-subscription: multicloud-operators-subscription: hub and spoke servic
CVE-2026-703989.6 CRITICALMulticloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamesp
CVE-2026-136228.8 HIGHKubevirt: virt-handler-rhel9: kubevirt: virt-handler migration proxy follows symlinks allo
CVE-2026-714738.5 HIGHAcm-search-v2-rhel9: search-v2-operator: addonfactory.getvaluesfromaddonannotation enables
CVE-2026-731227.7 HIGHMulticloud-operators-channel: multicloud-operators-channel: auto-generated role grants eve
CVE-2026-668787.7 HIGHMulticloud-operators-subscription: multicloud-operators-subscription: fetchchannelreferenc
CVE-2026-196547.5 HIGHRsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can all
CVE-2026-714697.5 HIGHAcm-search-v2-api-rhel9: search-v2-api: unbounded tokenreviews cache allows unauthenticate
CVE-2026-187266.5 MEDIUMOpen-iscsi: open-iscsi: denial of service in iscsiuio router advertisement parsing
CVE-2026-187276.5 MEDIUMOpen-iscsi: open-iscsi: integer underflow in iscsiuio dhcpv6 parsing
CVE-2026-718466.5 MEDIUMInsights-client: insights-client: clusterrole grants cluster-wide secrets get/list/watch b
CVE-2026-649276.4 MEDIUMMulticloud-operators-channel: multicloud-operators-channel: cross-namespace secret and con
CVE-2026-186635.9 MEDIUM389-ds-base: 389-ds-base: pre-authentication double-free in get_ldapmessage_controls_ext()
CVE-2026-191305.8 MEDIUMProvider-credential-controller: provider-credential-controller: cross-namespace credential
CVE-2026-195485.5 MEDIUMBinutils: binutils: multiple use-after-free in add_archive_element via lto plugin processi

IV. 関連脆弱性

V. CVE-2026-71471へのコメント

まだコメントはありません


コメントを残す