CVE-2026-76139
Awaiting Analysis Awaiting Analysis - Queue

Remote Code Execution in acm-operator-bundle

Vulnerability report for CVE-2026-76139, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-09-05

Assigner: redhat-SADP

Description

A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote attacker could exploit this vulnerability to inject malicious code, leading to unauthorized access to build resources and potential compromise of the resulting operator bundle.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-09-05
Generated
2026-09-09
AI Q&A
2026-08-20
EPSS Evaluated
2026-09-07
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat acm_operator_bundle *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-829 The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the acm-operator-bundle component downloading and executing a script from a remote source without verifying its authenticity. The script can access sensitive credentials like GitHub tokens and registry passwords used in the build environment. An attacker could exploit this to inject malicious code, gaining unauthorized access to build resources and potentially compromising the operator bundle.

Detection Guidance

This vulnerability involves untrusted remote scripts accessing sensitive credentials during the build process. Detection requires inspecting build logs and scripts for unauthorized downloads or credential exposure. Check for unexpected network connections during builds and verify script sources.

Impact Analysis

If you use or build acm-operator-bundle, an attacker could gain control over your build environment, steal sensitive credentials, or modify the operator bundle to include malicious code. This could lead to unauthorized access to your systems or data, depending on how the bundle is deployed.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements or HIPAA's security rules. Organizations using affected builds may face compliance breaches, legal penalties, or reputational damage due to potential data exposure or system compromise.

Mitigation Strategies

Review and audit the acm-operator-bundle build process to ensure all remote scripts are verified for authenticity and integrity before execution. Remove any untrusted scripts that download credentials or sensitive data during the build. Rotate exposed credentials like GitHub tokens and registry passwords immediately.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76139. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart