Description
A flaw was found in operator-sdk-builder. The containers-policy.json configuration file defaults to insecureAcceptAnything for container image registries that are not explicitly listed. This default setting causes signature verification to be entirely skipped for images pulled from these unlisted registries, which could allow for the use of untrusted or malicious container images.
Published: n/a
Score: 4.2 Medium
EPSS: n/a
KEV: No
Impact: Signature Verification Bypass
Action: Apply Patch
AI Analysis

Impact

A configuration flaw in operator‑sdk‑builder causes the containers‑policy.json file to default to insecureAcceptAnything for any container image registry that is not explicitly listed. With this default, the builder skips signature verification of images pulled from those registries, allowing attackers to inject untrusted or malicious containers. This flaw exposes the deployment process to compromised images that could execute arbitrary code or modify application behavior.

Affected Systems

The vulnerability applies to installations of operator‑sdk‑builder. No specific vendor or version information is provided, so all versions that use the default containers‑policy.json configuration are potentially affected.

Risk and Exploitability

The CVSS score is 4.2, indicating low severity, and the EPSS score is not available, while the vulnerability is not listed in CISA’s KEV catalog. The attack vector is likely network‑based, with an attacker providing a malicious image through an unlisted registry when the builder pulls container images. Although the risk is moderate, the consequence of executing malicious code in operator bundles makes early mitigation important.

Generated by OpenCVE AI on September 9, 2026 at 06:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Configure containers-policy.json to explicitly list trusted registries and set insecureAcceptAnything to false for all others.
  • Upgrade operator‑sdk‑builder to a release that removes the insecureAcceptAnything default or patches the vulnerability.
  • Audit existing container images from untrusted registries to ensure they are verified and free from tampering.

Generated by OpenCVE AI on September 9, 2026 at 06:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in operator-sdk-builder. The containers-policy.json configuration file defaults to insecureAcceptAnything for container image registries that are not explicitly listed. This default setting causes signature verification to be entirely skipped for images pulled from these unlisted registries, which could allow for the use of untrusted or malicious container images.
Title operator-sdk-builder: operator-sdk-builder: containers-policy.json defaults to insecureAcceptAnything for non-Red Hat registries
Weaknesses CWE-345
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-08T19:00:00Z

Links: CVE-2026-87054 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T07:00:09Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity