CVE-2026-75481 UNKNOWN

CVE-2026-75481

Published: 2026-08-17

Description

SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate it to administrator role, and authenticate with its bearer token to gain administrative control over all users and workspaces.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…