Description
A flaw was found in olm-operator-konflux-sample. The build pipelines use mutable floating tags to reference runtime base images instead of immutable SHA256 digests. This configuration allows for the content of the base images to be altered without detection, potentially leading to the introduction of malicious code or unexpected changes in the build process. An attacker could exploit this to compromise the integrity of the software supply chain.
Published: n/a
Score: 4.2 Medium
EPSS: n/a
KEV: No
Impact: Supply Chain Compromise
Action: Assess Impact
AI Analysis

Impact

Malware could be introduced into the software supply chain by using mutable floating tags for runtime base images. The build pipelines reference base images by name rather than by immutable SHA256 digests, allowing an attacker to replace these images undetected. The result is compromised build integrity and the risk of malicious code being embedded in the final output.

Affected Systems

The flaw affects the olm-operator-konflux-sample product. No specific vendor or product versions are listed, so all instances that use the default build configuration relying on mutable tags are potentially impacted.

Risk and Exploitability

Because the issue involves only the build process, the vulnerability does not grant direct remote code execution on deployed applications. The CVSS score of 4.2 indicates low severity, and no EPSS data is available. The analysis is inferred from the fact that an attacker would need to alter the image repository; without a KEV listing there is no evidence of active exploitation. Nevertheless, the potential for supply chain compromise means any organization using this operator should verify immutability of base images and restrict changes.

Generated by OpenCVE AI on September 9, 2026 at 06:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the CI/CD pipeline configuration to reference runtime base images by their immutable SHA256 digests instead of floating tags
  • Enforce immutability policies in the build process and restrict modification of image tags
  • Periodically audit the image registry for unexpected changes and ensure that any new or altered images are scanned for malicious content

Generated by OpenCVE AI on September 9, 2026 at 06:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in olm-operator-konflux-sample. The build pipelines use mutable floating tags to reference runtime base images instead of immutable SHA256 digests. This configuration allows for the content of the base images to be altered without detection, potentially leading to the introduction of malicious code or unexpected changes in the build process. An attacker could exploit this to compromise the integrity of the software supply chain.
Title olm-operator-konflux-sample: olm-operator-konflux-sample: Runtime base images referenced by mutable floating tags
Weaknesses CWE-829
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-08T19:00:00Z

Links: CVE-2026-87057 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T07:00:09Z

Weaknesses
  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere