PT-2026-48505 · Fission · Fission

CVE-2026-49823

·

Published

2026-06-10

·

Updated

2026-07-30

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fission versions prior to 1.24.0
Description An issue exists in the Fission serverless framework where the admission webhook fails to validate the namespace for the PackageRef.Namespace reference type. While Secret and ConfigMap reference types are namespace-validated, the lack of validation for PackageRef.Namespace allows for cross-namespace access.
Recommendations Update to version 1.24.0.

Exploit

Fix

Incorrect Authorization

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49823
GHSA-3R8V-2XMJ-5C39
GO-2026-5846
OPENSUSE-SU-2026:21483-1

Affected Products

Fission