Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-75481

HIGH NVD
CVSS Score 8.8
Severity HIGH
Published Aug 17, 2026
Vendor unknown

Description

SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate it to administrator role, and authenticate with its bearer token to gain administrative control over all users and workspaces.

References