Description
A flaw was found in konflux-operator-tasks. The GitHub workflows used by this component do not explicitly define their required permissions. This oversight means the workflows may inherit default access tokens that grant broader privileges than intended. Such excessive permissions could potentially allow an attacker to gain unauthorized access or perform actions beyond the intended scope, leading to information disclosure or unauthorized modifications.
Published: n/a
Score: 2.6 Low
EPSS: n/a
KEV: No
Impact: Unauthorized Access or Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The flaw resides in konflux-operator-tasks: its GitHub workflows do not specify explicit least-privilege permissions, causing them to inherit broader access tokens by default. This oversight can let an attacker obtain unauthorized access or execute actions beyond the intended scope, potentially leading to information disclosure or unauthorized modifications.

Affected Systems

konflux-operator-tasks is the affected component. No specific version information is provided in the current advisory, so all deployed instances of this component are potentially impacted.

Risk and Exploitability

The CVSS score of 2.6 indicates low severity, and the EPSS score is not available, suggesting limited likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. If an attacker can inject code or manipulate events in the GitHub workflows, the default token privileges could be leveraged to access settings, secrets, or repository contents, which is inferred from the description.

Generated by OpenCVE AI on September 9, 2026 at 06:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update konflux-operator-tasks to a version that includes explicit least-privilege permission blocks in its GitHub workflows.
  • Review the GitHub Actions workflow files within the component and set permissions to the minimum required scopes.
  • Apply fine-grained personal access tokens or deployment tokens for workflow execution, following GitHub’s best‑practice guidance.

Generated by OpenCVE AI on September 9, 2026 at 06:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in konflux-operator-tasks. The GitHub workflows used by this component do not explicitly define their required permissions. This oversight means the workflows may inherit default access tokens that grant broader privileges than intended. Such excessive permissions could potentially allow an attacker to gain unauthorized access or perform actions beyond the intended scope, leading to information disclosure or unauthorized modifications.
Title konflux-operator-tasks: konflux-operator-tasks: GitHub workflows lack explicit least-privilege permissions blocks
Weaknesses CWE-269
References
Metrics threat_severity

None

cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N'}

threat_severity

Low


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-08T19:00:00Z

Links: CVE-2026-87064 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T07:00:09Z

Weaknesses
  • CWE-269

    Improper Privilege Management