๐Ÿ” CVE Alert

CVE-2026-46612

HIGH 8.8

Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, the Fission storagesvc component registers archive CRUD handlers (/v1/archive GET / POST / DELETE and /v1/archives list) directly on its HTTP router without performing any authentication or authorization. Any caller able to reach the storagesvc ClusterIP โ€” including any other workload in the same Kubernetes cluster โ€” could enumerate archive IDs, download archives belonging to other tenants, upload arbitrary archive content, and delete archives. This issue has been patched in version 1.23.0.

CWE CWE-306
Vendor fission
Product fission
Published Jun 10, 2026
Last Updated Jun 10, 2026
Stay Ahead of the Next One

Get instant alerts for fission fission

Be the first to know when new high vulnerabilities affecting fission fission are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

fission / fission
< 1.23.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/fission/fission/security/advisories/GHSA-chf8-4hv6-8pg6 github.com: https://github.com/fission/fission/pull/3365 github.com: https://github.com/fission/fission/pull/3368 github.com: https://github.com/fission/fission/releases/tag/v1.23.0