Description
Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_options.kubernetes.serviceAccountName, and the Kubernetes backend in pipeline/backend/kubernetes/pod.go copies that pipeline-step value directly into the pod specification without administrator authorization. Any user with Push permission on a connected repository can therefore run pipeline pods under an arbitrary ServiceAccount in the pipeline namespace and inherit that account's RBAC permissions. When a privileged ServiceAccount is reachable, the attacker can exfiltrate secrets such as database credentials, API keys, and TLS certificates and may take over the cluster. This issue is fixed in version 3.16.0.
Published: 2026-09-15
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation through arbitrary ServiceAccount usage
Action: Immediate Patch
AI Analysis

Impact

Woodpecker is a CI/CD engine that, from version 1.0.0 through 3.16.0, exposes a Kubernetes backend flaw. The backend_options.kubernetes.serviceAccountName field allows pipeline steps to specify any ServiceAccount name, and the pod construction code copies this value directly into the pod spec without checking the requester’s authorization. Consequently, any user with push permission to a repository can trigger pipeline pods that run under an arbitrary ServiceAccount inside the pipeline namespace. If the chosen ServiceAccount possesses elevated RBAC rights, the attacker can read cluster secrets such as database credentials, API keys, and TLS certificates, and may even take full control of the Kubernetes cluster.

Affected Systems

The vulnerability affects the Woodpecker CI product, specifically versions ranging from 1.0.0 up to and including 3.16.0. The issue was addressed and fixed in the 3.16.0 release.

Risk and Exploitability

To date, the CVSS score of 9.0 marks this flaw as critical. The EPSS score of < 1 % indicates a very low but non‑zero likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalogue. The likely attack vector is an authorised repository push user; the attacker can trigger pipeline execution that runs under a chosen ServiceAccount, thereby elevating privileges, exfiltrating secrets, or taking over the cluster. The flaw is mitigated by upgrading to version 3.16.0 or later, which removes the unchecked ServiceAccount bridging.

Generated by OpenCVE AI on September 20, 2026 at 16:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Woodpecker CI to version 3.16.0 or later to apply the vendor fix.
  • Limit repository push permissions to trusted personnel only, ensuring that only authorised users can trigger pipeline executions.
  • Configure or restrict the Service appropriately privileged accounts can be used.
  • If the Kubernetes backend is not required, disable or remove it from the Woodpecker configuration to eliminate the vulnerable execution path.

Generated by OpenCVE AI on September 20, 2026 at 16:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-qf34-295c-26v8 Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend
History

Tue, 15 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Woodpecker-ci
Woodpecker-ci woodpecker
Vendors & Products Woodpecker-ci
Woodpecker-ci woodpecker

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_options.kubernetes.serviceAccountName, and the Kubernetes backend in pipeline/backend/kubernetes/pod.go copies that pipeline-step value directly into the pod specification without administrator authorization. Any user with Push permission on a connected repository can therefore run pipeline pods under an arbitrary ServiceAccount in the pipeline namespace and inherit that account's RBAC permissions. When a privileged ServiceAccount is reachable, the attacker can exfiltrate secrets such as database credentials, API keys, and TLS certificates and may take over the cluster. This issue is fixed in version 3.16.0.
Title Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend
Weaknesses CWE-269
CWE-862
References
Metrics cvssV4_0

{'score': 9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Woodpecker-ci Woodpecker
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T03:56:27.876Z

Reserved: 2026-07-10T16:27:03.094Z

Link: CVE-2026-61549

cve-icon Vulnrichment

Updated: 2026-09-15T15:19:35.499Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T15:17:20.110

Modified: 2026-09-30T17:51:36.337

Link: CVE-2026-61549

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:00:13Z

Weaknesses