Description
A flaw was found in operator-sdk-builder. Due to an oversight in the Containerfile configuration, the final built container image runs with root privileges by default. This increases the attack surface of the container, as any process executed within it will have elevated permissions. If a malicious actor compromises the container, they could leverage these root privileges to perform unauthorized actions, potentially leading to a broader system compromise.
Published: n/a
Score: 4.2 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

A flaw in the operator-sdk-builder Containerfile leaves the final built image with a USER root directive that is never overridden. As a result, any process executed inside the image runs with full root privileges, expanding the attack surface and allowing a compromised container to perform unauthorized actions that could reach beyond the container boundaries.

Affected Systems

This issue affects operator images built with operator-sdk-builder when the default Containerfile configuration is used. No specific vendor or version list is provided, but any environment that generates operator images without explicitly changing the USER directive will inherit this root execution.

Risk and Exploitability

The CVSS score of 4.2 indicates moderate severity, and the EPSS score is currently unavailable. The vulnerability is not listed in the CISA KEV catalog. The flaw is classified as CWE-250. While the lack of a public EPSS score limits precise risk forecasting, the fact that the image runs as root by default creates a clear privilege escalation path. An attacker who can gain code execution inside the container, or who can influence the image content, may be able to perform elevated operations that could lead to host compromise if additional escape conditions are met.

Generated by OpenCVE AI on September 9, 2026 at 06:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Audit the Containerfile in operator-sdk-builder to remove the default USER root directive or replace it with a non‑root user.
  • Rebuild operator images using the corrected Containerfile, ensuring the final image starts with a non‑root user.
  • Verify that images used in deployments no longer default to root by inspecting the USER directive or using image scanning tools.

Generated by OpenCVE AI on September 9, 2026 at 06:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in operator-sdk-builder. Due to an oversight in the Containerfile configuration, the final built container image runs with root privileges by default. This increases the attack surface of the container, as any process executed within it will have elevated permissions. If a malicious actor compromises the container, they could leverage these root privileges to perform unauthorized actions, potentially leading to a broader system compromise.
Title operator-sdk-builder: operator-sdk-builder: Final container image runs as root (USER root never reverted)
Weaknesses CWE-250
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-08T19:00:00Z

Links: CVE-2026-87053 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T07:00:09Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges