← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 17, 2026 · 20:36via CVEFeed

CVE-2026-75481 - SkyPilot Authentication Bypass via Service Account Role Escalation

Brief

CVE ID : CVE-2026-75481

Published : Aug. 17, 2026, 8:36 p. m.

  • 31 minutes ago

Description : SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate it to administrator role, and authenticate with its bearer token to gain administrative control over all users and workspaces.

Severity: 8.8

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed