multicluster engine for Kubernetes 2.1 vulnerability

A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to inject and execute arbitrary code during the build. The consequence is a compromised build process, potentially leading to the distribution of malicious software.

Published 19 Aug 2026Updated 6 Sep 20268 sources
CVSS 7.7

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.