Impact
A flaw exists in the search-v2-operator that permits a privileged Custom Resource editor to supply unsanitized values for imageOverride, arguments, and environment variables. By controlling these fields, an attacker can mount arbitrary secrets into a search container’s environment or replace the container image with an attacker‑controlled one. The resulting privilege escalation can lead to full cluster compromise because the ServiceAccount used by the operator impersonates other accounts with broad permissions.
Affected Systems
The vulnerability affects Red Hat Advanced Cluster Management for Kubernetes 2 (acm version 2). No specific sub‑version was listed; any installation using this operator is potentially impacted.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity, and the EPSS score is not available, so exploitation probability cannot be quantified. The attacker must hold privileges sufficient to create or modify Search Custom Resources. If only such users exist, the risk is high, especially given the operator’s use of a ServiceAccount that can impersonate other accounts. The vulnerability is not listed in the CISA KEV catalog, but the potential impact warrants immediate attention.
OpenCVE Enrichment