NPM · AUGUST 2026 · EARLY WARNING

search-v2-operator npm Package Vulnerability: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Affected component
search-v2-operator (npm)
Patched version
Not yet available
CVE-2026-71470

An early warning has been issued for a critical vulnerability in the search-v2-operator npm package. This flaw could allow a privileged user to manipulate Search CR fields, potentially leading to privilege escalation and full cluster compromise.

What happened

A flaw has been identified in the search-v2-operator npm package, which allows a privileged user to manipulate Search CR fields without proper validation. This manipulation can lead to privilege escalation and potential full cluster compromise. The vulnerability is tracked under CVE-2026-71470 with a CVSS score of 9.1, indicating a critical severity level. The flaw reportedly enables a privileged user to mount arbitrary secrets into a search container's environment or replace the container image with an attacker-controlled one.

The vulnerability is under investigation, and no authoritative version range has been published yet. Users of the search-v2-operator npm package should review their cluster configurations for any unauthorized changes and stay updated on the situation.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If search-v2-operator is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using the search-v2-operator npm package, you may be affected. However, no authoritative version range has been published yet. Consult the primary sources for the most current information.

What should I do right now?

Monitor the primary sources for updates on the vulnerability. Review your cluster configurations for any unauthorized changes. Stay tuned for a patched version of search-v2-operator.

Is there a patched version available?

No official fix has been published yet. Monitor the primary sources for updates on a patched version of search-v2-operator.

Sources

Join the 0Day waitlist →

← Back to all threats