« Volver al listado

CVE-2026-75569

Estado: Pendiente de análisisAlta (7.7)—

A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to inject and execute arbitrary code during the build. The consequence is a compromised build process, potentially leading to the distribution of malicious software.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de cadena de suministro: el proceso de construcción ejecuta scripts remotos sin verificación (firma/pinning), permitiendo inyección de código malicioso. Impactos: ejecución de comandos en la compilación y corrupción de artefactos distribuidos.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-75569",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-75569",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-08-20T14:00:29.833872Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secalert@redhat.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.7,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 1.3
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:/a:redhat:multicluster_engine:2.10::el9"
          ],
          "vendor": "Red Hat",
          "product": "multicluster engine for Kubernetes 2.10",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787263075",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "multicluster-engine/mce-operator-bundle",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:multicluster_engine:2.11::el9"
          ],
          "vendor": "Red Hat",
          "product": "multicluster engine for Kubernetes 2.11",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787321579",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "multicluster-engine/mce-operator-bundle",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:multicluster_engine:2.17::el9"
          ],
          "vendor": "Red Hat",
          "product": "multicluster engine for Kubernetes 2.17",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787083639",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "multicluster-engine/mce-operator-bundle",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:multicluster_engine:2.6::el9"
          ],
          "vendor": "Red Hat",
          "product": "multicluster engine for Kubernetes 2.6",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787317415",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "multicluster-engine/mce-operator-bundle",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:multicluster_engine:2.8::el9"
          ],
          "vendor": "Red Hat",
          "product": "multicluster engine for Kubernetes 2.8",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787318262",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "multicluster-engine/mce-operator-bundle",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:multicluster_engine:2.9::el9"
          ],
          "vendor": "Red Hat",
          "product": "multicluster engine for Kubernetes 2.9",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787287150",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "multicluster-engine/mce-operator-bundle",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-19T21:17:37.287",
  "references": [
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:59634",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:59636",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:59637",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:59638",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:59642",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:59643",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2026-75569",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2519849",
      "source": "secalert@redhat.com"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1357"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to inject and execute arbitrary code during the build. The consequence is a compromised build process, potentially leading to the distribution of malicious software."
    }
  ],
  "lastModified": "2026-09-29T20:17:23.893",
  "sourceIdentifier": "secalert@redhat.com"
}