HIGH
SkyPilot Authentication Bypass via Service Account Role Escalation
Published Aug 17, 2026
8.7
HIGHCVSS 4.0
EPSS 0.36%
Description
SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate it to administrator role, and authenticate with its bearer token to gain administrative control over all users and workspaces.
Affected products
-
- Version 0StatusaffectedConstraints<=0.13.1rc1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Skypilot-Org | Skypilot | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-60393 Advisory
- https://github.com/skypilot-org/skypilot product
- https://github.com/skypilot-org/skypilot/blob/master/sky/users/server.py technical-description
- https://github.com/skypilot-org/skypilot/commit/8a3e00259cd374e662cd876c037164bcb070f78e patch
- https://github.com/skypilot-org/skypilot/issues/9846 exploitissue-tracking
- https://www.vulncheck.com/advisories/skypilot-authentication-bypass-via-service-account-role-escalation third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-60393 | Advisory | |
| https://github.com/skypilot-org/skypilot | product | |
| https://github.com/skypilot-org/skypilot/blob/master/sky/users/server.py | technical-description | |
| https://github.com/skypilot-org/skypilot/commit/8a3e00259cd374e662cd876c037164bcb070f78e | patch | |
| https://github.com/skypilot-org/skypilot/issues/9846 | exploitissue-tracking | |
| https://www.vulncheck.com/advisories/skypilot-authentication-bypass-via-service-account-role-escalation | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 17, 2026
Updated Sep 24, 2026
Reserved Aug 17, 2026
Link CVE-2026-75481
CISA Vulnrichment
Updated Aug 18, 2026
ENISA EUVD
EUVD-2026-60393 Assigner VulnCheck
Published Aug 17, 2026
Updated Sep 24, 2026
Exploited since n/a
Link EUVD-2026-60393