Bug 2519852 (CVE-2026-76139)

Summary: CVE-2026-76139 acm-operator-bundle: acm-operator-bundle: Bundle build execs unpinned stolostron/release@master with full build credentials
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: gparvin, rhaigner, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote attacker could exploit this vulnerability to inject malicious code, leading to unauthorized access to build resources and potential compromise of the resulting operator bundle.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-19 19:03:39 UTC
The acm-operator-bundle build fetches whatever is at stolostron/release@master HEAD at run time and execs tools/konflux/common/process-triggering-pr.sh from it. There is no commit-SHA pin, no checksum, and no signature verification. The exec'd script inherits the full environment of the triggering step, including a GitHub App token scoped to all repos under github.repository_owner, registry passwords for registry.redhat.io/registry.stage.redhat.io/quay.io, and write access to the bundle PR that becomes the shipped ACM operator bundle. (Related weakness: CWE-494, Download of Code Without Integrity Check.)

Upstream Jira: ACM-38668