Description
A flaw was found in operator-foundry. Untrusted external actors can exploit over-permissive GitHub access tokens and Google Cloud Platform (GCP) Workload Identity Federation credentials granted to a third-party reusable workflow. By invoking this workflow on untrusted-triggerable events without sufficient authorization checks, an attacker could gain highly privileged access to GitHub and cloud resources, potentially leading to unauthorized control.
Published: n/a
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Unauthorized Access
Action: Patch Immediately
AI Analysis

Impact

A flaw in operator‑foundry allows external actors to call a third‑party reusable workflow that is granted overly permissive GitHub access tokens and Google Cloud Platform Workload Identity Federation credentials. By triggering this workflow on untrusted events without proper authorization checks, an attacker can obtain highly privileged access to both GitHub and cloud resources, potentially taking complete control. This vulnerability is categorized as an access‑control weakness (CWE‑269).

Affected Systems

The vulnerability affects the operator‑foundry GitHub action/repository that provides reusable workflows utilizing GITHUB_TOKEN and GCP WIF secrets. No specific version information is supplied, so any instance of operator‑foundry that offers the vulnerable workflow and accepts external triggers is at risk.

Risk and Exploitability

The CVSS score of 8.7 reflects a high severity, and while an EPSS score is not available, the absence of a KEV listing does not reduce the risk of exploitation. The likely attack vector is an untrusted‑triggerable event invoking the vulnerable workflow. With no obvious runtime checks, an attacker can leverage the over‑permissive tokens to access GitHub repositories and GCP projects, achieving data exfiltration or further lateral movement.

Generated by OpenCVE AI on September 9, 2026 at 06:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade operator‑foundry to the latest patch that removes over‑permissive secrets and adds proper authorization checks for reusable workflows.
  • Restrict reusable workflow triggers to trusted event types only, and enable required approval steps before execution.
  • Revoke or replace any GITHUB_TOKEN and GCP WIF credentials used by the workflow with least‑privilege secrets, or disable them for untrusted triggers.

Generated by OpenCVE AI on September 9, 2026 at 06:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in operator-foundry. Untrusted external actors can exploit over-permissive GitHub access tokens and Google Cloud Platform (GCP) Workload Identity Federation credentials granted to a third-party reusable workflow. By invoking this workflow on untrusted-triggerable events without sufficient authorization checks, an attacker could gain highly privileged access to GitHub and cloud resources, potentially leading to unauthorized control.
Title operator-foundry: operator-foundry: Over-permissive GITHUB_TOKEN and GCP WIF secrets granted to third-party reusable workflow on untrusted-triggerable events
Weaknesses CWE-269
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'}

threat_severity

Important


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-08T19:00:00Z

Links: CVE-2026-87049 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T07:00:09Z

Weaknesses
  • CWE-269

    Improper Privilege Management