CVE-2026-75481
8.8skypilot-org · skypilot
SkyPilot contains a privilege management vulnerability that allows authenticated users to improperly grant administrator roles when updating service account permissions.
Executive summary
A vulnerability in SkyPilot allows authenticated users to perform unauthorized privilege escalation, posing a significant risk to administrative control over service accounts.
Vulnerability
This is an improper privilege management flaw (CWE-269) where the application fails to validate if an authenticated user has the necessary authorization to elevate service account roles. The vulnerability is exploitable by an authenticated user with low privileges.
Business impact
Successful exploitation allows an attacker to gain unauthorized administrative control over service accounts, which could lead to full system compromise or unauthorized access to sensitive cloud resources managed by SkyPilot. With a CVSS score of 8.8, this vulnerability represents a high-severity risk that could facilitate lateral movement and data exfiltration within an organization.
Remediation
Immediate Action: Upgrade to the latest version of SkyPilot where the validation logic for service account permissions has been corrected.
Proactive Monitoring: Review audit logs for suspicious modifications to service account permissions or unexpected role grants to non-administrative users.
Compensating Controls: Implement strict identity and access management policies that limit the number of users capable of modifying service account configurations.
Exploitation status
Public Exploit Available: No confirmed public exploit available.
Analyst recommendation
The severity of this privilege escalation vulnerability necessitates immediate attention. Administrators should verify the current version of their SkyPilot deployment and prioritize upgrading to a secure version to prevent potential unauthorized administrative access.