CVE-2026-61549Critical· 9.0▾ MidnightWoodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_options.kubernetes.serviceAccountName, and the Kubernetes backend in pipeline/backend/kubernetes/pod.go copies that pip…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 49.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
— → 9
high → critical
Last analysed / modified upstream
0.2%
Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_options.kubernetes.serviceAccountName, and the Kubernetes backend in pipeline/backend/kubernetes/pod.go copies that pipeline-step value directly into the pod specification without administrator authorization. Any user with Push permission on a connected repository can therefore run pipeline pods under an arbitrary ServiceAccount in the pipeline namespace and inherit that account's RBAC permissions. When a privileged ServiceAccount is reachable, the attacker can exfiltrate secrets such as database credentials, API keys, and TLS certificates and may take over the cluster. This issue is fixed in version 3.16.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
go.woodpecker-ci.org/woodpecker/v3 < 3.16.0github.com/woodpecker-ci/woodpecker >= 1.0.0, <= 1.0.4go.woodpecker-ci.org/woodpecker/v2 <= 2.8.3Patched in:
go.woodpecker-ci.org/woodpecker/v3 3.16.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54168Medium· 6.5Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories
CVE-2026-16772High· 8.1In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges
CVE-2026-49819Critical· 9.8UpSnap is a wake on lan web app
CVE-2026-73842Critical· 9.0OpenChoreo is a complete, open-source developer platform for Kubernetes
CVE-2023-40034High· 8.1Woodpecker does not validate webhook before changing any data
CVE-2026-75837Critical· 9.1Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction