PT-2026-48505 · Fission · Fission
CVE-2026-49823
·
Published
2026-06-10
·
Updated
2026-07-30
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Fission versions prior to 1.24.0
Description
An issue exists in the Fission serverless framework where the admission webhook fails to validate the namespace for the
PackageRef.Namespace reference type. While Secret and ConfigMap reference types are namespace-validated, the lack of validation for PackageRef.Namespace allows for cross-namespace access.Recommendations
Update to version 1.24.0.
Exploit
Fix
Incorrect Authorization
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fission