THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-76139 (HIGH 8.0) — A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords,

[NVD] CVE-2026-76139 (HIGH 8.0) — A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords,

mednvdPublished 2026-08-19

CVE-2026-76139 CVSS: 8.0 HIGH Published: 2026-08-19T21:17:38.070

A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote attacker could

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-76139