Database/Control plane, storage & DevOps
SkyPilot (API server, service account role update authorization): SkyPilot never checks whether the caller is entitled
Impact
SkyPilot never checks whether the caller is entitled to grant the administrator role when updating service account permissions. Any authenticated user creates a service account, promotes it to admin, then authenticates with its bearer token and owns every user and every workspace - which on SkyPilot means control of the clusters and cloud accounts it provisions GPUs in.
Who can reach it
Any authenticated SkyPilot user with API server access. No admin rights needed to start.
What to do
Upgrade SkyPilot past the fixed commit (8a3e0025) and restart the API server. Then enumerate existing service accounts and their roles - an attacker who already ran this leaves a legitimate-looking admin service account behind that the upgrade does not remove.
References
Related entries
- Citrix NetScaler ADC/Gateway: memory overflow in Gateway and AAA vservers causes denial of serviceCVE-2026-8452 · Citrix NetScaler ADC / Gateway (Gateway and AAA virtual servers)High
- Jenkins: config.xml nested objects reachable via Stapler give authenticated users remote code executionCVE-2026-84645 · Jenkins controller (config.xml submission, Stapler request routing)High
- Jenkins Stapler: form data binding instantiates configuration types the target field never expectedCVE-2026-84647 · Jenkins Stapler (form data binding type restriction)High
- Jenkins: unescaped system log metadata lets an agent-controlled process store XSS in the controller UICVE-2026-84648 · Jenkins controller (system log viewer, log record metadata escaping)High
- Jenkins Stapler: CSRF crumb embedded in generated JavaScript leaks to same-site attackersCVE-2026-84649 · Jenkins Stapler (dynamically generated JavaScript endpoint, CSRF crumb)High
- Jenkins: transient fields cannot be excluded from deserialization of submitted configurationCVE-2026-84650 · Jenkins controller (XStream configuration deserialization, transient fields)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.