highVulnerability

CVE-2026-61549

### Impact A privilege escalation vulnerability affects Woodpecker instances using the **Kubernetes backend**. The pipeline option `backend_options.kubernetes.serviceAccountName` was passed directly to the pod spec without any admin gating. **Who is impacted:** any operator running the Kubernetes backend. Any user with **Push** permission on a connected repository can run pipeline pods under an arbitrary ServiceAccount in the pipeline namespace, gaining that account's RBAC permissions. If a privileged ServiceAccount is reachable in that namespace, this can lead to secret exfiltration (database credentials, API keys, TLS certs) and full cluster takeover. ### Patches https://github.com/woodpecker-ci/woodpecker/pull/6792 ### Workarounds Operators who cannot upgrade immediately can mitigate by any of: - **Restrict Push access** on repositories connected to the Kubernetes-backed instance to trusted users only. - **Harden the pipeline namespace**: ensure no privileged ServiceAccount exists or is bound in the namespace where pipeline pods run; keep the `default` ServiceAccount minimally privileged. - **Disable ServiceAccount token automounting** for ServiceAccounts that should not be used by pipelines. - **Enforce an admission policy** (e.g. OPA/Gatekeeper, Kyverno, or a ValidatingAdmissionPolicy) that rejects pipeline pods setting an unexpected `serviceAccountName`. - **Use a dedicated, isolated namespace** per org/instance with no sensitive RBAC bindings. ### Resources - Vulnerable option introduced in commit `609ba481b5e912f59aaae8ca7bc22b44523c5e37` - Affected versions: `v1.0.0` through `v3.15.0` - Source: `pipeline/backend/kubernetes/backend_options.go` (field `ServiceAccountName`), `pipeline/backend/kubernetes/pod.go` (assigned to pod spec with no gating)

Properties

ghsa_id
GHSA-qf34-295c-26v8
severity
high
summary
Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend
cve_id
CVE-2026-61549
is_ghsa_only
false
ghsa_published
2026-07-14T20:29:32Z
source_url
https://github.com/advisories/GHSA-qf34-295c-26v8
ghsa_updated
2026-07-14T20:29:33Z

Related Entities (9)

VULNERABLE_TO (3)

[Software]go/go.woodpecker-ci.org/woodpecker/v3
[Software]go/go.woodpecker-ci.org/woodpecker/v2
[Software]go/github.com/woodpecker-ci/woodpecker

AFFECTS (3)

[Software]go/go.woodpecker-ci.org/woodpecker/v2
[Software]go/go.woodpecker-ci.org/woodpecker/v3
[Software]go/github.com/woodpecker-ci/woodpecker

HAS_WEAKNESS (2)

[Weakness]Improper Privilege Management
[Weakness]Missing Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-61549 — Ninja Signal Threat Intelligence | Ninja Signal