CVE-2026-75481 – SkyPilot

CVSS 8.8 IMPORTANT Zero Day – Immediate Deployment

“A standard authenticated user can turn a service account into full administrative control.”

SkyPilot contains a High-severity privilege escalation flaw in service account permission handling. CVE-2026-75481 allows an authenticated attacker to create a service account, assign it the administrator role without proper authorization, and use its bearer token to gain administrative access across users and workspaces. The CVSS score is 8.8, which is High severity.

Public proof-of-concept material is available for the vulnerability.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-269
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.