{"id":"CVE-2026-61549","aliases":["GO-2026-5992"],"url":"https://o3.security/vulnerability/CVE-2026-61549","summary":"Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend","details":"### Impact\n\nA privilege escalation vulnerability affects Woodpecker instances using the **Kubernetes backend**.\n\nThe pipeline option `backend_options.kubernetes.serviceAccountName` was passed directly to the pod spec without any admin gating.\n\n**Who is impacted:** any operator running the Kubernetes backend. Any user with **Push** permission on a connected repository can run pipeline pods under an arbitrary ServiceAccount in the pipeline namespace, gaining that account's RBAC permissions. If a privileged ServiceAccount is reachable in that namespace, this can lead to secret exfiltration (database credentials, API keys, TLS certs) and full cluster takeover.\n\n### Patches\n\nhttps://github.com/woodpecker-ci/woodpecker/pull/6792\n\n### Workarounds\n\nOperators who cannot upgrade immediately can mitigate by any of:\n\n- **Restrict Push access** on repositories connected to the Kubernetes-backed instance to\n  trusted users only.\n- **Harden the pipeline namespace**: ensure no privileged ServiceAccount exists or is bound in\n  the namespace where pipeline pods run; keep the `default` ServiceAccount minimally privileged.\n- **Disable ServiceAccount token automounting** for ServiceAccounts that should not be used by\n  pipelines.\n- **Enforce an admission policy** (e.g. OPA/Gatekeeper, Kyverno, or a ValidatingAdmissionPolicy)\n  that rejects pipeline pods setting an unexpected `serviceAccountName`.\n- **Use a dedicated, isolated namespace** per org/instance with no sensitive RBAC bindings.\n\n### Resources\n\n- Vulnerable option introduced in commit `609ba481b5e912f59aaae8ca7bc22b44523c5e37`\n- Affected versions: `v1.0.0` through `v3.15.0`\n- Source: `pipeline/backend/kubernetes/backend_options.go` (field `ServiceAccountName`),\n  `pipeline/backend/kubernetes/pod.go` (assigned to pod spec with no gating)","published":"2026-07-14T20:29:32Z","modified":"2026-07-21T19:19:18.601959177Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"go.woodpecker-ci.org/woodpecker/v3","fixedVersion":"3.16.0"},{"ecosystem":"Go","name":"github.com/woodpecker-ci/woodpecker","fixedVersion":null},{"ecosystem":"Go","name":"go.woodpecker-ci.org/woodpecker/v2","fixedVersion":null}],"fix":{"url":"https://github.com/woodpecker-ci/woodpecker/pull/6792","label":"woodpecker-ci/woodpecker#6792"},"references":[{"type":"WEB","url":"https://github.com/woodpecker-ci/woodpecker/security/advisories/GHSA-qf34-295c-26v8"},{"type":"WEB","url":"https://github.com/woodpecker-ci/woodpecker/pull/6792"},{"type":"PACKAGE","url":"https://github.com/woodpecker-ci/woodpecker"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-21T19:19:18.601959177Z"}}