CVE-2026-75569
A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to inject and execute arbitrary code during the build. The consequence is a compromised build process, potentially leading to the distribution of malicious software.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.7
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
- EPSS probability
- 0.38%
- CWE
- CWE-829, CWE-1357
- Published
- 2026-08-19
- Last modified
- 2026-09-08
Affected products
- Red Hat multicluster engine for Kubernetes 2.9.0
- Red Hat multicluster engine for Kubernetes 2.11
- Red Hat multicluster engine for Kubernetes 2.17
- Red Hat multicluster engine for Kubernetes 2.6
- Red Hat multicluster engine for Kubernetes 2.8
- Red Hat multicluster engine for Kubernetes 2.9
- Red Hat multicluster engine for Kubernetes 2.10
- Red Hat multicluster engine for Kubernetes 2.1
Weakness type
Related vulnerabilities
- CVE-2026-79721 — Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer,...
- CVE-2026-86504 — In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev...
- CVE-2026-86169 — Axolotl through 0.18.0 Remote Code Execution via Multipack Patching
- CVE-2026-82525 — Exterro FTK Imager < 8.3 XXE via Report.xml XSLT Processing
- CVE-2026-58569 — Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability....
- CVE-2026-18252 — Inclusion of Functionality from Untrusted Control Sphere in GitLab
- CVE-2026-76139 — Acm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/release@master with full build credentials
- CVE-2026-22306 — Critical flaw impacting OZOLS ERP's automatic update channel