High severity8.0NVD Advisory· Published Aug 19, 2026· Updated Sep 8, 2026
CVE-2026-76139
CVE-2026-76139
Description
A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote attacker could exploit this vulnerability to inject malicious code, leading to unauthorized access to build resources and potential compromise of the resulting operator bundle.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
8- access.redhat.com/errata/RHSA-2026:60399nvd
- access.redhat.com/errata/RHSA-2026:60400nvd
- access.redhat.com/errata/RHSA-2026:60401nvd
- access.redhat.com/errata/RHSA-2026:60402nvd
- access.redhat.com/errata/RHSA-2026:60403nvd
- access.redhat.com/errata/RHSA-2026:60404nvd
- access.redhat.com/security/cve/CVE-2026-76139nvd
- bugzilla.redhat.com/show_bug.cginvd
News mentions
0No linked articles in our index yet.