Ghostwire

CVE-2026-75481: SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service...

HIGH CVSS 0.0

Published: August 17, 2026 | Last Modified: August 17, 2026

Description

SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate it to administrator role, and authenticate with its bearer token to gain administrative control over all users and workspaces.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References