CVE-2026-61549
Last modified
CVE-2026-61549 is a critical-severity vulnerability rated 9/10 on the CVSS scale. Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_options.kubernetes.serviceAccountName, and the Kubernetes backend in pipeline/backend/kubernetes/pod.go copies that pipeline-step value directly into the pod specification without administrator authorization.
Description
Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_options.kubernetes.serviceAccountName, and the Kubernetes backend in pipeline/backend/kubernetes/pod.go copies that pipeline-step value directly into the pod specification without administrator authorization. Any user with Push permission on a connected repository can therefore run pipeline pods under an arbitrary ServiceAccount in the pipeline namespace and inherit that account's RBAC permissions. When a privileged ServiceAccount is reachable, the attacker can exfiltrate secrets such as database credentials, API keys, and TLS certificates and may take over the cluster. This issue is fixed in version 3.16.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| woodpecker-ci | woodpecker | >= 1.0.0, < 3.16.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-61549?
How severe is CVE-2026-61549?
How do I fix CVE-2026-61549?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6153A vulnerability was identified in code-projects Vehicle Show…7.3
- CVE-2026-61534Yayson is a library for serializing and reading JSON API dat…9.1
- CVE-2026-61536Banks generates meaningful LLM prompts using a simple templa…7.5
- CVE-2026-61539Xinference is an inference API for running open-source, spee…10
- CVE-2026-6154A security flaw has been discovered in Totolink A7100RU 7.4c…9.8
- CVE-2026-61544libp2p-rust is the official Rust language implementation of …8.2
- CVE-2026-6155A weakness has been identified in Totolink A7100RU 7.4cu.231…9.8
- CVE-2026-61554emp3r0r is a C2 designed by Linux users for Linux environmen…7.5
- CVE-2026-61555OpenEXR is the reference implementation and specification fo…5.5
- CVE-2026-61556LiquidJS is a Shopify / GitHub Pages compatible template eng…8.7
- CVE-2026-61559`@zereight/mcp-gitlab` is a Model Context Protocol server fo…9.6
- CVE-2026-6156A security vulnerability has been detected in Totolink A7100…9.8
Are you affected by CVE-2026-61549?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
