Description
A flaw was found in konflux-operator-tasks. Tekton task steps within this component run with root privileges without sufficient security hardening. This lack of defense-in-depth controls, such as restricted capabilities or disabled privilege escalation, could potentially allow an attacker to escalate privileges or perform unauthorized actions if another vulnerability is exploited within the root-run process.
Published: n/a
Score: 2.6 Low
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Assess Impact
AI Analysis

Impact

A flaw in konflux-operator-tasks allows Tekton task steps to run as root without proper security hardening. This absence of defense‑in‑depth controls, notably missing restrictions on capabilities or privilege escalation, leads to potential privilege escalation if an attacker can gain execution within that root process. The vulnerability is classified as CWE-250, indicating the ability to run code with elevated privileges.

Affected Systems

The affected system is the konflux-operator-tasks component used in Tekton pipelines. Any deployment of this component may be impacted since the CVE does not specify version ranges. Administrators should verify their Tekton task configurations for root execution of task steps.

Risk and Exploitability

The CVSS score of 2.6 reflects a low overall risk when considered alone, and no EPSS score is available to indicate exploitation likelihood. Because the flaw relies on a pre‑existing vulnerability within the root‑run process to be abused, the practical threat is limited unless other weaknesses exist. The patch is not listed in CISA KEV, suggesting no known widespread exploitation. Nevertheless, any untrusted Tekton tasks that run as root could be a vector for privilege escalation if combined with other vulnerabilities.

Generated by OpenCVE AI on September 9, 2026 at 07:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Configure Tekton task securityContext to run as non‑root or the least privileged user.
  • Disable privilege escalation and limit container capabilities in the task specification.
  • Enforce least‑privilege policies and regularly audit task definitions for excessive privileges.

Generated by OpenCVE AI on September 9, 2026 at 07:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in konflux-operator-tasks. Tekton task steps within this component run with root privileges without sufficient security hardening. This lack of defense-in-depth controls, such as restricted capabilities or disabled privilege escalation, could potentially allow an attacker to escalate privileges or perform unauthorized actions if another vulnerability is exploited within the root-run process.
Title konflux-operator-tasks: konflux-operator-tasks: Tekton task steps run as root without defense-in-depth securityContext hardening
Weaknesses CWE-250
References
Metrics threat_severity

None

cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N'}

threat_severity

Low


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-08T19:00:00Z

Links: CVE-2026-87065 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T07:30:06Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges