Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-76139— Acm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/release@master with full build credentials

Quick assessment

Affected
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

发现 ACM Operator Bundle 存在一个安全漏洞。该组件的构建过程会从远程来源下载并执行一个脚本,但未对脚本的真实性和完整性进行验证。该脚本能够访问构建环境中使用的敏感凭据,例如 GitHub 访问令牌和镜像仓库密码。远程攻击者可利用此漏洞注入恶意代码,从而获得对构建资源的未授权访问,并可能导致最终生成的 Operator Bundle 遭到破坏。

CVSS 8.0 · High EPSS 0.33% · P25

Affected Version Matrix 1

VendorProduct Version RangeStatus
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2 any affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-76139

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Acm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/release@master with full build credentials
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote attacker could exploit this vulnerability to inject malicious code, leading to unauthorized access to build resources and potential compromise of the resulting operator bundle.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
从非可信控制范围包含功能例程
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2 - cpe:/a:redhat:acm:2

II. Public POCs for CVE-2026-76139

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-76139

登录查看更多情报信息。

Vendor Advisories for CVE-2026-76139 (2)

Same Patch Batch · Red Hat · 2026-08-19 · 10 CVEs total

CVE-2026-70496 9.9 CRITICAL Search-v2-operator: search-v2-operator: operator clusterrole is cluster-admin equivalent v
CVE-2026-66794 9.3 CRITICAL Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluste
CVE-2026-71470 9.1 CRITICAL Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow uns
CVE-2026-75569 7.7 HIGH Mce-operator-bundle: mce-operator-bundle: bundle-generation business logic fetched from mu
CVE-2026-76235 7.5 HIGH Cockpit-ws: cockpit: cockpit-ws: unauthenticated remote memory leak via cockpitlang cookie
CVE-2026-76827 6.8 MEDIUM Search-indexer: search-indexer: update/delete operations not scoped to caller's cluster (c
CVE-2026-18874 6.2 MEDIUM Volsync-addon-controller: volsync-addon-controller: annotation values rendered into yaml v
CVE-2026-75900 6.1 MEDIUM Swtpm: swtpm: out-of-bounds read in swtpm_nvram_checkheader due to sizeof(pointer) vs size
CVE-2026-76166 4.3 MEDIUM Modcluster-core: mod_cluster advertise listener: unauthenticated dos via crafted multicast

IV. Related Vulnerabilities

V. Comments for CVE-2026-76139

No comments yet


Leave a comment