This is a simple one and used to be the same problem with SCCM builds on Microsoft.
The image builder processes uses a hard coded default username and password which can be used to exploit container builds.
Refer to this post for more:
https://github.com/advisories/GHSA-9224-ggvw-wh7v