search-v2-operator npm Package Vulnerability: Early Warning
- Severity
- CRITICAL
- CVSS
- 9.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Affected component
- search-v2-operator (npm)
- Patched version
- Not yet available
An early warning has been issued for a critical vulnerability in the search-v2-operator npm package. This flaw could allow a privileged user to manipulate Search CR fields, potentially leading to privilege escalation and full cluster compromise.
What happened
A flaw has been identified in the search-v2-operator npm package, which allows a privileged user to manipulate Search CR fields without proper validation. This manipulation can lead to privilege escalation and potential full cluster compromise. The vulnerability is tracked under CVE-2026-71470 with a CVSS score of 9.1, indicating a critical severity level. The flaw reportedly enables a privileged user to mount arbitrary secrets into a search container's environment or replace the container image with an attacker-controlled one.
The vulnerability is under investigation, and no authoritative version range has been published yet. Users of the search-v2-operator npm package should review their cluster configurations for any unauthorized changes and stay updated on the situation.
What to do about it
- Monitor the primary sources for updates on the vulnerability.
- Review your cluster configurations for any unauthorized changes.
- No official fix has been published yet. Stay tuned to the primary sources for updates on a patched version of search-v2-operator.
- Consider implementing additional security measures to protect your cluster until a fix is available.
How 0Day would have caught this
search-v2-operator is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using the search-v2-operator npm package, you may be affected. However, no authoritative version range has been published yet. Consult the primary sources for the most current information.
What should I do right now?
Monitor the primary sources for updates on the vulnerability. Review your cluster configurations for any unauthorized changes. Stay tuned for a patched version of search-v2-operator.
Is there a patched version available?
No official fix has been published yet. Monitor the primary sources for updates on a patched version of search-v2-operator.