← Back

CVE-2026-32604

nvd nist
Published: Apr 20, 2026Modified: Jun 17, 2026

JSON object

Loading...
9.9
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.1 / Impact: 6.0
Source: security-advisories@github.com (Secondary)

Description

Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands very simply on the clouddriver pods. This can expose credentials, remove files, or inject resources easily. Versions 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2 contain a patch. As a workaround, disable the gitrepo artifact types.

Affected (3)

Spinnaker
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Linuxfoundation
Before 2025.3.2
From 2025.4.0 to 2025.4.2
From 2026.0.0 to 2026.0.1

References (5)

Source: security-advisories@github.com
ProductRelease Notes
Source: security-advisories@github.com
ProductRelease Notes
Source: security-advisories@github.com
ProductRelease Notes
Source: security-advisories@github.com
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.