VYPR

acm-search-v2-api-rhel9

by Red Hat

CVEs (3)

  • CVE-2026-71472CriAug 17, 2026
    risk 0.59cvss 9.1epss 0.01

    A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or SQL statements. This occurs because the WORK_MEM string provided in the Search…

  • CVE-2026-71471CriAug 12, 2026
    risk 0.59cvss 9.0epss 0.01

    A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This allows the attacker to deploy an…

  • CVE-2026-71468MedAug 11, 2026
    risk 0.34cvss 5.3epss 0.00

    A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access…