CVE-2026-76139
A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote attacker could exploit this vulnerability to inject malicious code, leading to unauthorized access to build resources and potential compromise of the resulting operator bundle.
Scoring
- Severity
- HIGH
- CVSS base score
- 8
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.45%
- CWE
- CWE-829
- Published
- 2026-08-19
- Last modified
- 2026-09-08
Affected products
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.14.0
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.13
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.14
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.17
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.11
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.15
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.16
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.16.0
Weakness type
Related vulnerabilities
- CVE-2026-79721 — Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer,...
- CVE-2026-86504 — In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev...
- CVE-2026-86169 — Axolotl through 0.18.0 Remote Code Execution via Multipack Patching
- CVE-2026-82525 — Exterro FTK Imager < 8.3 XXE via Report.xml XSLT Processing
- CVE-2026-58569 — Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability....
- CVE-2026-18252 — Inclusion of Functionality from Untrusted Control Sphere in GitLab
- CVE-2026-75569 — Mce-operator-bundle: all github actions pinned by mutable tag, not commit sha
- CVE-2026-22306 — Critical flaw impacting OZOLS ERP's automatic update channel