Important severity8.7NVD Advisory· Published Sep 8, 2026
operator-foundry: operator-foundry: Over-permissive GITHUB_TOKEN and GCP WIF secrets granted to third-party reusable workflow on untrusted-triggerable events
CVE-2026-87049
Description
operator-foundry: operator-foundry: Over-permissive GITHUB_TOKEN and GCP WIF secrets granted to third-party reusable workflow on untrusted-triggerable events
Affected products
1Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.