CVE-2026-75481 – SkyPilot
CVSS 8.8
IMPORTANT
Zero Day – Immediate Deployment
“A standard authenticated user can turn a service account into full administrative control.”
SkyPilot contains a High-severity privilege escalation flaw in service account permission handling. CVE-2026-75481 allows an authenticated attacker to create a service account, assign it the administrator role without proper authorization, and use its bearer token to gain administrative access across users and workspaces. The CVSS score is 8.8, which is High severity.
Public proof-of-concept material is available for the vulnerability.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-269
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.