Database/Control plane, storage & DevOps
SkyPilot (API server, service account role update authorization): SkyPilot never checks whether the caller is entitled
Impact
SkyPilot never checks whether the caller is entitled to grant the administrator role when updating service account permissions. Any authenticated user creates a service account, promotes it to admin, then authenticates with its bearer token and owns every user and every workspace - which on SkyPilot means control of the clusters and cloud accounts it provisions GPUs in.
Who can reach it
Any authenticated SkyPilot user with API server access. No admin rights needed to start.
What to do
Upgrade SkyPilot past the fixed commit (8a3e0025) and restart the API server. Then enumerate existing service accounts and their roles - an attacker who already ran this leaves a legitimate-looking admin service account behind that the upgrade does not remove.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.