CVE-2026-75569CWE-1357

CVE-2026-75569

High · published August 20, 2026

CVSS v3.1
7.7
EPSS
0%
Percentile
31.3
In the wild
Unconfirmed
What it is

A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to inject and execute arbitrary code during the build. The consequence is a compromised build process, potentially leading to the distribution of malicious software.

The record
Technical detail
CVSS v3.1
7.7 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00382 · 31.3th percentile
Weakness
CWE-1357 · Reliance on Insufficiently Trustworthy Component
Published
2026-08-20T01:17Z
References (8)
EPSS history
Timeline
  • 19 AUG 20:47Z
    Mce-operator-bundle: mce-operator-bundle: bundle-generation business logic fetched from mutable stolostron/release@master
    cvelistv5