A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or SQL statements. This occurs because the WORK_MEM string provided in the Search CR is not properly validated before being used in a bash script and an SQL query. Successful exploitation could lead to arbitrary code execution within the privileged postgres pod, potentially compromising the system.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-17 20:16
Updated : 2026-08-27 04:16
NVD link : CVE-2026-71472
Mitre link : CVE-2026-71472
CVE.ORG link : CVE-2026-71472
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
