Description
A flaw was found in konflux-operator-tasks. GitHub Actions within this component are configured to use mutable tags or branches instead of specific, immutable commit SHAs. This vulnerability could allow a remote attacker to introduce malicious code into the build process if they compromise the referenced mutable tag or branch. Such a compromise could lead to unauthorized code execution or integrity issues within the affected system.
Published: n/a
Score: 4.2 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized code execution through altered CI workflows
Action: Patch immediately
AI Analysis

Impact

The vulnerability arises when GitHub Actions in the konflux-operator-tasks component reference mutable tags or branches instead of specific commit SHAs. This oversight permits a remote actor, if able to modify the referenced tag or branch, to inject malicious code into the build pipeline. The result could be the execution of unauthorized code or corruption of the build artifacts, compromising the integrity of the affected system.

Affected Systems

The flaw targets the konflux-operator-tasks project. No specific product versions or vendor details are listed in the CNA data; therefore, any installation of this component that relies on GitHub Actions with mutable references is potentially impacted.

Risk and Exploitability

The CVSS score of 4.2 places this issue in the low‑to‑moderate severity range. Because EPSS data is not available and the vulnerability is not listed in CISA KEV, the likelihood of exploitation is uncertain, but the remote path via compromised tags or branches is feasible. Attackers need only influence the mutable reference in the CI definition to achieve the impact described.

Generated by OpenCVE AI on September 9, 2026 at 06:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update konflux-operator-tasks or its workflow definitions to use immutable commit SHAs for every GitHub Action reference.
  • If a patch is not available, lock all mutable tags and branches referenced in the CI, ensuring the pipeline only pulls from fixed commits.
  • Implement branch protection rules and require signed commits for the paths that influence CI configuration to prevent unauthorized changes.

Generated by OpenCVE AI on September 9, 2026 at 06:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in konflux-operator-tasks. GitHub Actions within this component are configured to use mutable tags or branches instead of specific, immutable commit SHAs. This vulnerability could allow a remote attacker to introduce malicious code into the build process if they compromise the referenced mutable tag or branch. Such a compromise could lead to unauthorized code execution or integrity issues within the affected system.
Title konflux-operator-tasks: konflux-operator-tasks: GitHub Actions referenced by mutable tag/branch instead of commit SHA
Weaknesses CWE-829
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-08T19:00:00Z

Links: CVE-2026-87062 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T07:00:09Z

Weaknesses
  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere