Impact
A vulnerability in acm-search-v2-rhel9 allows an attacker who has administrative patch privileges on the hub cluster to set the Collector.ImageOverride field to an arbitrary container image. When the Search Custom Resource is applied, that image is deployed to every managed cluster through the Search Operator, giving the attacker remote code execution capability across the entire fleet. The flaw is a classic improper authorization error, classified as CWE‑829.
Affected Systems
All instances of Red Hat Advanced Cluster Management for Kubernetes 2 are affected. The product is identified by the CPE cpe:/a:redhat:acm:2. No specific sub‑versions are listed, so the issue applies to every release of this product until a fix is deployed.
Risk and Exploitability
The CVSS score of 9 indicates critical severity, while the EPSS score of 1 % suggests that the exploitation probability is low but non‑zero. The vulnerability is not listed in CISA’s KEV catalogue, but that does not diminish the risk. An attacker only needs administrative patch rights on the hub cluster; once that requirement is met, a single privileged configuration change triggers widespread remote code execution. The attack vector is internal access to the hub, making it a high‑impact risk for environments with overly permissive or misconfigured administrator privileges.
OpenCVE Enrichment