CVE-2026-75481: Improper Privilege Management in skypilot-org skypilot
SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate it to administrator role, and authenticate with its bearer token to gain administrative control over all users and workspaces.
AI Analysis
Technical Summary
The vulnerability in skypilot-org skypilot arises from a failure to properly validate whether authenticated users have the right to grant administrator roles during updates to service account permissions. Exploiting this flaw, an attacker can create a service account, escalate its privileges to administrator, and then use its bearer token to authenticate with full administrative control over all users and workspaces within the system. This privilege escalation vulnerability has a CVSS 4.0 score of 8.7, indicating high severity.
Potential Impact
Successful exploitation allows an attacker with authenticated access to escalate privileges to administrator level, gaining full administrative control over all users and workspaces in the affected skypilot environment. This could lead to unauthorized access, modification, or disruption of critical resources managed by skypilot.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict authenticated user permissions to minimize the risk of privilege escalation and monitor for suspicious privilege changes related to service accounts.
CVE-2026-75481: Improper Privilege Management in skypilot-org skypilot
Description
SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate it to administrator role, and authenticate with its bearer token to gain administrative control over all users and workspaces.
CVSS v4.0
Score 8.7high
Affected software
skypilot-org
skypilot
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in skypilot-org skypilot arises from a failure to properly validate whether authenticated users have the right to grant administrator roles during updates to service account permissions. Exploiting this flaw, an attacker can create a service account, escalate its privileges to administrator, and then use its bearer token to authenticate with full administrative control over all users and workspaces within the system. This privilege escalation vulnerability has a CVSS 4.0 score of 8.7, indicating high severity.
Potential Impact
Successful exploitation allows an attacker with authenticated access to escalate privileges to administrator level, gaining full administrative control over all users and workspaces in the affected skypilot environment. This could lead to unauthorized access, modification, or disruption of critical resources managed by skypilot.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict authenticated user permissions to minimize the risk of privilege escalation and monitor for suspicious privilege changes related to service accounts.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-17T19:59:23.460Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a83721bbf8831d539891cdd
Added to database: 08/17/2026, 20:42:03 UTC
Last enriched: 09/25/2026, 02:41:12 UTC
Last updated: 10/02/2026, 02:46:06 UTC
Views: 60
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.