CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-61549

highcovered by 1 sourcefirst seen 2026-07-14
Impact A privilege escalation vulnerability affects Woodpecker instances using the Kubernetes backend. The pipeline option backend_options.kubernetes.serviceAccountName was passed directly to the pod spec without any admin gating. Who is impacted: any operator running the Kubernetes backend. Any user with Push permission on a connected repository can run pipeline pods under an arbitrary ServiceAccount in the pipeline namespace, gaining that account's RBAC permissions. If a privileged ServiceAccount is reachable in that namespace, this can lead to secret exfiltration (database credentials, API keys, TLS certs) and full cluster takeover. Patches https://github.com/woodpecker-ci/woodpecker/pull/6792 Workarounds Operators who cannot upgrade immediately can mitigate by any of: - Restrict Push access on repositories connected to the Kubernetes-backed instance to trusted users only. - Harden the pipeline namespace: ensure no privileged ServiceAccount exists or is bound in the namespace where pipeline pods run; keep the default ServiceAccount minimally privileged. - Disable ServiceAccount token automounting for ServiceAccounts that should not be used by pipelines. - Enforce an admission policy (e.g. OPA/Gatekeeper, Kyverno, or a ValidatingAdmissionPolicy) that rejects pipeline pods setting an unexpected serviceAccountName. - Use a dedicated, isolated namespace per org/instance with no sensitive RBAC bindings. Resources - Vulnerable option introduced in commit 609ba481b5e912f59aaae8ca7bc22b44523c5e37 - Affected versions: v1.0.0 through v3.15.0 - Source: pipeline/backend/kubernetes/backend_options.go (field ServiceAccountName), pipeline/backend/kubernetes/pod.go (assigned to pod spec with no gating)

⚡ Watch CVE-2026-61549

Get an email if CVE-2026-61549 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-61549

CVE.org record

Embed the live status

CVE-2026-61549 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-61549 status](https://www.csirts.com/badge/CVE-2026-61549)](https://www.csirts.com/cve/CVE-2026-61549)