PT-2026-48511 · Fission · Fission

CVE-2026-50566

·

Published

2026-06-10

·

Updated

2026-07-30

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fission versions prior to 1.24.0
Description An issue exists in the Kubernetes-native serverless framework where a tenant with environments.fission.io create/update RBAC permissions can deploy containers with privileged access, allowPrivilegeEscalation, or dangerous capabilities within the Fission function or builder namespace. These containers are scheduled under the executor's high-privilege service account, which can lead to a container-sandbox escape, providing unauthorized access to the host filesystem and network, and potentially resulting in the compromise of the node and the entire cluster.
Recommendations Update to version 1.24.0.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50566
GHSA-M63V-2G9W-2W6V
GO-2026-5857
OPENSUSE-SU-2026:21483-1

Affected Products

Fission