CVE-2026-75481
SkyPilot Authentication Bypass via Service Account Role Escalation
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate it to administrator role, and authenticate with its bearer token to gain administrative control over all users and workspaces.
| CWE | CWE-269 |
| Vendor | skypilot-org |
| Product | skypilot |
| Published | Aug 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for skypilot-org skypilot
Be the first to know when new high vulnerabilities affecting skypilot-org skypilot are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
skypilot-org / skypilot
0 โค 0.13.1rc1
References
github.com: https://github.com/skypilot-org/skypilot/issues/9846 github.com: https://github.com/skypilot-org/skypilot github.com: https://github.com/skypilot-org/skypilot/commit/8a3e00259cd374e662cd876c037164bcb070f78e github.com: https://github.com/skypilot-org/skypilot/blob/master/sky/users/server.py vulncheck.com: https://www.vulncheck.com/advisories/skypilot-authentication-bypass-via-service-account-role-escalation
Credits
๐ geo-chen