CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-50141

highcovered by 1 sourcefirst seen 2026-07-14
Impact A vulnerability in Woodpecker CI's gRPC layer allowed any authenticated agent to impersonate any other agent on the same server by injecting a forged agent_id value into outgoing gRPC metadata. The server correctly verified the JWT token but then discarded the verified agent identity in favor of the client-supplied value. Patches Direct patch: https://github.com/woodpecker-ci/woodpecker/pull/6567 Later proper fix: https://github.com/woodpecker-ci/woodpecker/pull/6569 Workarounds Disable org agents (WOODPECKER_DISABLE_USER_AGENT_REGISTRATION=true) and delete existing ones Resources Public ref: https://github.com/woodpecker-ci/woodpecker/issues/6541 Private com: https://github.com/woodpecker-ci/woodpecker-security/issues/21

⚡ Watch CVE-2026-50141

Get an email if CVE-2026-50141 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-50141

CVE.org record

Embed the live status

CVE-2026-50141 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-50141 status](https://www.csirts.com/badge/CVE-2026-50141)](https://www.csirts.com/cve/CVE-2026-50141)