High severity8.8NVD Advisory· Published Aug 17, 2026
CVE-2026-75481
CVE-2026-75481
Description
SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate it to administrator role, and authenticate with its bearer token to gain administrative control over all users and workspaces.
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.