CVE-2026-61549: CWE-269: Improper Privilege Management in woodpecker-ci woodpecker
Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_options.kubernetes.serviceAccountName, and the Kubernetes backend in pipeline/backend/kubernetes/pod.go copies that pipeline-step value directly into the pod specification without administrator authorization. Any user with Push permission on a connected repository can therefore run pipeline pods under an arbitrary ServiceAccount in the pipeline namespace and inherit that account's RBAC permissions. When a privileged ServiceAccount is reachable, the attacker can exfiltrate secrets such as database credentials, API keys, and TLS certificates and may take over the cluster. This issue is fixed in version 3.16.0.
AI Analysis
Technical Summary
Woodpecker CI/CD engine versions >=1.0.0 and <3.16.0 have a vulnerability in the Kubernetes backend where the serviceAccountName field for pipeline pods is set directly from user-controlled input without administrator authorization. This improper privilege management (CWE-269) enables any user with Push permission to run pipeline pods under arbitrary ServiceAccounts within the pipeline namespace, inheriting their RBAC permissions. If a privileged ServiceAccount is accessible, attackers can exfiltrate secrets such as database credentials, API keys, and TLS certificates, and potentially take over the Kubernetes cluster. The issue is resolved in version 3.16.0.
Potential Impact
An attacker with Push permission on a repository can escalate privileges by running pipeline pods under arbitrary Kubernetes ServiceAccounts, including privileged ones. This can lead to exfiltration of sensitive secrets and full cluster takeover. The CVSS 4.0 score is 9 (critical), reflecting the high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Upgrade Woodpecker to version 3.16.0 or later, where this vulnerability is fixed. Until then, restrict Push permissions to trusted users only and review Kubernetes ServiceAccount permissions to minimize risk. Patch status is confirmed fixed in 3.16.0.
CVE-2026-61549: CWE-269: Improper Privilege Management in woodpecker-ci woodpecker
Description
Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_options.kubernetes.serviceAccountName, and the Kubernetes backend in pipeline/backend/kubernetes/pod.go copies that pipeline-step value directly into the pod specification without administrator authorization. Any user with Push permission on a connected repository can therefore run pipeline pods under an arbitrary ServiceAccount in the pipeline namespace and inherit that account's RBAC permissions. When a privileged ServiceAccount is reachable, the attacker can exfiltrate secrets such as database credentials, API keys, and TLS certificates and may take over the cluster. This issue is fixed in version 3.16.0.
CVSS v4.0
Score 9.0critical
Affected software
woodpecker-ci
woodpecker
pkg:github/woodpecker-ci/woodpeckerRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Woodpecker CI/CD engine versions >=1.0.0 and <3.16.0 have a vulnerability in the Kubernetes backend where the serviceAccountName field for pipeline pods is set directly from user-controlled input without administrator authorization. This improper privilege management (CWE-269) enables any user with Push permission to run pipeline pods under arbitrary ServiceAccounts within the pipeline namespace, inheriting their RBAC permissions. If a privileged ServiceAccount is accessible, attackers can exfiltrate secrets such as database credentials, API keys, and TLS certificates, and potentially take over the Kubernetes cluster. The issue is resolved in version 3.16.0.
Potential Impact
An attacker with Push permission on a repository can escalate privileges by running pipeline pods under arbitrary Kubernetes ServiceAccounts, including privileged ones. This can lead to exfiltration of sensitive secrets and full cluster takeover. The CVSS 4.0 score is 9 (critical), reflecting the high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Upgrade Woodpecker to version 3.16.0 or later, where this vulnerability is fixed. Until then, restrict Push permissions to trusted users only and review Kubernetes ServiceAccount permissions to minimize risk. Patch status is confirmed fixed in 3.16.0.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-10T16:27:03.094Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa95dfa55bf5e2cf5f98f51
Added to database: 09/15/2026, 15:02:18 UTC
Last enriched: 09/15/2026, 15:16:41 UTC
Last updated: 09/15/2026, 23:10:50 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.