THREAT OPS › Threat News › [NVD] CVE-2026-76139 (HIGH 8.0) — A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords,
[NVD] CVE-2026-76139 (HIGH 8.0) — A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords,
CVE-2026-76139 CVSS: 8.0 HIGH Published: 2026-08-19T21:17:38.070
A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote attacker could
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-76139cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-76139