Code Injection Vulnerability in ACM Operator Bundle from Red Hat
CVE-2026-76139

8HIGH

What is CVE-2026-76139?

A vulnerability exists in the ACM Operator Bundle due to a flaw in its build process that allows a remote script to be downloaded and executed without proper validation of its origin. This oversight can result in unauthorized access to sensitive credentials, such as GitHub tokens and registry passwords, which are essential for the build environment. By exploiting this vulnerability, attackers could inject malicious code, jeopardizing the integrity of the operator bundle and potentially allowing for unauthorized manipulation of build resources.

Affected Version(s)

Red Hat Advanced Cluster Management for Kubernetes 2.11 1787704547

Red Hat Advanced Cluster Management for Kubernetes 2.13 1787712120

Red Hat Advanced Cluster Management for Kubernetes 2.14 1787704476

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.