PT-2026-50677 · Unknown · Woodpecker

·

CVE-2026-50141

·

Published

2026-06-18

·

Updated

2026-07-30

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Woodpecker versions 3.0.0 through 3.14.0
Description A flaw in the gRPC layer of the CI/CD engine allows an authenticated agent to impersonate any other agent on the same server. This occurs because the server verifies the JWT (JSON Web Token) but subsequently ignores the verified identity, accepting a forged agent id value provided in the outgoing gRPC metadata instead.
Recommendations Update to version 3.14.1. As a temporary workaround, disable organization agents by setting WOODPECKER DISABLE USER AGENT REGISTRATION=true and delete existing agents.

Exploit

Fix

IDOR

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50141
GHSA-G7MM-9VX7-JM7H
GO-2026-5976
OPENSUSE-SU-2026:21483-1

Affected Products

Woodpecker