CVE-2026-75481 - SkyPilot Authentication Bypass via Service Account Role Escalation
Brief
CVE ID : CVE-2026-75481
Published : Aug. 17, 2026, 8:36 p. m.
- 31 minutes ago
Description : SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate it to administrator role, and authenticate with its bearer token to gain administrative control over all users and workspaces.
Severity: 8.8
- HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
