Remote Code Execution Vulnerability in Quay Builder QEMU Affects Red Hat
CVE-2026-85469

8HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
16 September 2026

What is CVE-2026-85469?

A significant vulnerability has been identified in Quay Builder QEMU, which can be exploited by an attacker leveraging the upstream 'Noelware/docker-manifest-action' within the release workflow. This flaw is due to the use of a mutable branch, allowing arbitrary code execution. This can lead to serious security breaches, such as the exfiltration of sensitive registry credentials and the deployment of malicious container images. Additionally, the default GitHub token being exposed amplifies the risk, making it essential for users to assess their security posture and apply necessary mitigations.

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.