PT-2026-51444 · Maven+3 · Io.Spinnaker.Orca:Orca-Core+2
CVE-2026-44795
·
Published
2026-06-22
·
Updated
2026-07-21
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Spinnaker versions prior to 2026.1.0
Spinnaker versions prior to 2026.0.3
Spinnaker versions prior to 2025.4.4
Spinnaker versions prior to 2025.3.3
Description
Unsafe YAML processing bypasses safe deserialization during CloudFormation deployments or CloudFoundry baking. The use of a non-safe constructor allows the arbitrary loading of Java classes, which can lead to remote code execution (RCE), a process where an attacker executes malicious code on a remote machine.
Recommendations
Update to version 2026.1.0.
Update to version 2026.0.3.
Update to version 2025.4.4.
Update to version 2025.3.3.
Disable the CloudFormation system and CloudFoundry baking operations.
Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Io.Spinnaker.Orca:Orca-Core
Io.Spinnaker.Rosco:Rosco-Core
Spinnaker