PatchSiren cyber security CVE debrief
CVE-2026-85469 Red Hat CVE debrief
A flaw in quay-builder-qemu allows remote attackers to exploit the upstream `Noelware/docker-manifest-action` by compromising its mutable branch, injecting arbitrary code, and exfiltrating sensitive registry credentials or publishing malicious images. The workflow also exposes the default GitHub token, increasing the severity of the compromise. This vulnerability affects deployments relying on quay-builder-qemu and the integrity of the GitHub workflow. Defenders should assess exposure and prioritize verification of the workflow's integrity, focusing on ensuring that the `Noelware/docker-manifest-action` is pinned to an immutable commit.
- Vendor
- Red Hat
- Product
- Red Hat Quay 3
- CVSS
- HIGH 8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for quay-builder-qemu deployments, GitHub workflow configurations, and sensitive registry credential management should assess exposure and prioritize verification of the workflow's integrity.
Why it matters
CVE-2026-85469 allows remote attackers to inject arbitrary code in quay-builder-qemu, leading to sensitive data exfiltration or malicious image publication. Defenders should prioritize verifying workflow integrity and ensuring the `Noelware/docker-manifest-action` is pinned to an immutable commit.
- Remote code injection and arbitrary code execution in quay-builder-qemu deployments
- Exfiltration of sensitive registry credentials
- Publication of malicious images
- Potential lateral movement and compromise of dependent systems
Technical summary
The flaw in quay-builder-qemu allows remote attackers to compromise the upstream `Noelware/docker-manifest-action` by exploiting its mutable branch, leading to arbitrary code injection and sensitive registry credentials exfiltration or malicious image publication. This vulnerability arises from the use of a mutable branch in the `Noelware/docker-manifest-action`, which allows an attacker to inject malicious code. The exposure of the default GitHub token increases the severity of the compromise, as it could be used to further manipulate the workflow or access sensitive information.
Defensive priority
Defenders should prioritize verifying the integrity of the quay-builder-qemu workflow and ensuring that the `Noelware/docker-manifest-action` is pinned to a specific, immutable commit.
Recommended defensive actions
- Verify the integrity of the quay-builder-qemu workflow
- Ensure that the `Noelware/docker-manifest-action` is pinned to a specific, immutable commit
- Review and update the workflow to prevent exposure of sensitive tokens
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the flaw in quay-builder-qemu and its potential impact. However, the corpus does not establish versions, exploitation, impact, or remediation, which require verification from the supplied official sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-85469 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-85469
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-85469 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-85469
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-85469
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.