CVE-2026-75481

Source
https://cve.org/CVERecord?id=CVE-2026-75481
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75481.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-75481
Published
2026-08-17T20:36:06.800Z
Modified
2026-08-20T03:30:23.966312723Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
SkyPilot Authentication Bypass via Service Account Role Escalation
Details

SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate it to administrator role, and authenticate with its bearer token to gain administrative control over all users and workspaces.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-269"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75481.json"
}
References

Affected packages

Git / github.com/skypilot-org/skypilot

Affected ranges

Type
GIT
Repo
https://github.com/skypilot-org/skypilot
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.13.1rc1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

Other
nightly-20251217
untagged-ba5e4d688ad5317df6db
v0.*
v0.4.0-rc1
v0.5.0-rc1
v1.*
v1.0.0.dev20260723
v1.0.0.dev20260724
v1.0.0.dev20260727
v1.0.0.dev20260728
v1.0.0.dev20260729
v1.0.0.dev20260730
v1.0.0.dev20260731
v1.0.0.dev20260801
v1.0.0.dev20260802
v1.0.0.dev20260804
v1.0.0.dev20260805
v1.0.0.dev20260806
v1.0.0.dev20260807
v1.0.0.dev20260808
v1.0.0.dev20260810
v1.0.0.dev20260811
v1.0.0.dev20260812
v1.0.0.dev20260813
v1.0.0.dev20260814
v1.0.0.dev20260815

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75481.json"