CVE-2026-75481: SkyPilot Authentication Bypass via Service Account Role Escalation
SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate it to administrator role, and authenticate with its bearer token to gain administrative control over all users and workspaces.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-75481?
CVE-2026-75481 is classified as high severity with a score of 8.8.
How do I fix CVE-2026-75481?
To resolve CVE-2026-75481, ensure that proper role validation is implemented for service account permissions.
What is the risk associated with CVE-2026-75481?
CVE-2026-75481 poses a risk level of 79, indicating significant potential for exploitation.
What type of attack does CVE-2026-75481 enable?
CVE-2026-75481 allows attackers to escalate service account permissions to gain administrative control.
Who is affected by CVE-2026-75481?
Any users with the ability to create service accounts in SkyPilot are at risk due to CVE-2026-75481.