Red HatCVE-2026-76139
Red Hat acm-operator-bundle. The build process: untrusted functionality included
High8.0CVE-2026-76139 · Published Aug 19, 2026 · updated Sep 8, 2026
A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote attacker could exploit this vulnerability to inject malicious code, leading to unauthorized access to build resources and potential compromise of the resulting operator bundle.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-829
- www.cve.org/CVERecord?id=CVE-2026-76139
- nvd.nist.gov/vuln/detail/CVE-2026-76139
- access.redhat.com/errata/RHSA-2026:60399
- access.redhat.com/errata/RHSA-2026:60400
- access.redhat.com/errata/RHSA-2026:60401
- access.redhat.com/errata/RHSA-2026:60402
- access.redhat.com/errata/RHSA-2026:60403
- access.redhat.com/errata/RHSA-2026:60404
- access.redhat.com/security/cve/CVE-2026-76139
- bugzilla.redhat.com/show_bug.cgi?id=2519852
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 19 | Red Hat search-indexer. This vulnerability: protection mechanism failure | Medium6.8 | No fix yet |
| Aug 19 | Red Hat mce-operator-bundle. The build process fetches: remote code execution | High7.7 | No fix yet |
| Aug 19 | Red Hat Advanced Cluster Management for Kubernetes 2: improper access control | Critical9.9 | No fix yet |
| Aug 19 | Red Hat: authentication bypass | Critical9.3 | No fix yet |
| Aug 19 | Red Hat volsync-addon-controller. This vulnerability: code injection | Medium6.2 | No fix yet |
| Aug 19 | Red Hat search-v2-operator. This vulnerability: privilege escalation | Critical9.1 | No fix yet |