A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-50545

CVE-2026-50545: Fission Privilege Escalation Vulnerability

CVE-2026-50545 is a privilege escalation vulnerability in Fission, a Kubernetes-native serverless framework. Unvalidated podSpec fields allow dangerous configurations in generated pods. Learn about technical details, affected versions, and mitigation.

Published: June 11, 2026

CVE-2026-50545 Overview

CVE-2026-50545 is a privilege escalation vulnerability in Fission, an open-source Kubernetes-native serverless framework. The flaw affects all Fission releases prior to version 1.24.0. The Environment.spec.runtime.podSpec and spec.builder.podSpec passthrough fields lacked validation, and the MergePodSpec function propagated dangerous fields into generated pods. Authenticated users with permission to create or modify Fission Environment resources can inject arbitrary pod specifications. This enables container breakout, host access, and cluster-wide privilege escalation. The maintainers patched the issue in Fission v1.24.0. The vulnerability is tracked as [CWE-269: Improper Privilege Management].

Critical Impact

Authenticated tenants can inject privileged pod specifications through Fission Environment objects, escalating from namespace-scoped access to full cluster compromise.

Affected Products

  • Fission versions prior to 1.24.0
  • Fission Environment controller (spec.runtime.podSpec)
  • Fission Environment controller (spec.builder.podSpec)

Discovery Timeline

  • 2026-06-10 - CVE-2026-50545 published to NVD
  • 2026-06-10 - Last updated in NVD database

Technical Details for CVE-2026-50545

Vulnerability Analysis

Fission lets users define Environment custom resources that describe runtime and builder containers. Each Environment includes optional podSpec fields used to customize the underlying Kubernetes pod. Prior to v1.24.0, Fission's MergePodSpec helper copied user-supplied pod specifications directly into the controller-generated pods without filtering sensitive fields. Attackers with rights to create or update Environment objects can set fields such as hostPID, hostNetwork, hostPath volumes, privileged: true security contexts, custom serviceAccountName values, or nodeSelector and tolerations that pin pods onto control-plane nodes. The resulting pod inherits these dangerous attributes when the Fission executor reconciles the Environment. This converts a constrained namespace-scoped role into the effective permissions of the Fission service account, often cluster-admin. The flaw maps to [CWE-269] and produces a scope change because the privileges of the spawned pod exceed those of the requesting principal.

Root Cause

The root cause is missing input validation in the Environment admission and reconcile path. MergePodSpec performed a structural merge instead of an allow-list filter. Fission trusted the controller boundary and did not reject security-sensitive fields supplied by tenants.

Attack Vector

An attacker authenticates to the Kubernetes API with permission to create or modify Fission Environment resources in any namespace they control. They submit an Environment manifest containing a podSpec with privileged settings or host mounts. When Fission spawns the runtime or builder pod, it applies the attacker-controlled spec and runs it under the Fission executor's service account. The attacker then executes code inside the privileged pod and pivots to the host or other workloads.

No verified public exploit code is available. See the GitHub Security Advisory GHSA-wmgg-3p4h-48x7 for technical details.

Detection Methods for CVE-2026-50545

Indicators of Compromise

  • Fission Environment objects containing podSpec fields with privileged: true, hostPID: true, hostNetwork: true, or hostPath volume mounts.
  • Pods created by the Fission executor running with non-default serviceAccountName values or scheduled onto control-plane nodes.
  • Unexpected exec or attach API calls against Fission-managed pods in the fission-function or fission-builder namespaces.

Detection Strategies

  • Audit all Environment custom resources for the presence of spec.runtime.podSpec or spec.builder.podSpec fields and review their contents.
  • Enable Kubernetes audit logging on environments.fission.io create and update verbs, and alert on tenants modifying these resources.
  • Apply Pod Security Admission in restricted or baseline mode on Fission namespaces to surface and block non-conforming pods at admission time.

Monitoring Recommendations

  • Ingest Kubernetes audit logs and container runtime telemetry into a centralized analytics platform for correlation across the cluster.
  • Monitor Fission executor pods for runtime anomalies such as new processes, host filesystem access, and outbound network traffic to unexpected destinations.
  • Track changes to Fission ClusterRoleBindings and service accounts to detect post-exploitation persistence.

How to Mitigate CVE-2026-50545

Immediate Actions Required

  • Upgrade Fission to version 1.24.0 or later in every cluster that runs the platform.
  • Inventory existing Environment resources and remove any unauthorized podSpec content before upgrading.
  • Restrict RBAC permissions on environments.fission.io to a small set of trusted operators.

Patch Information

The vulnerability is fixed in Fission v1.24.0. The fix lands in pull request #3390 and pull request #3391, which add validation to MergePodSpec and reject dangerous fields. Refer to the GitHub Security Advisory GHSA-wmgg-3p4h-48x7 for the full vendor advisory.

Workarounds

  • Enforce Pod Security Admission in restricted mode on Fission namespaces to block privileged pods even if a malicious Environment is created.
  • Deploy an admission controller policy (OPA Gatekeeper or Kyverno) that rejects Environment resources containing podSpec.securityContext.privileged, hostPID, hostNetwork, hostPath, or custom serviceAccountName fields.
  • Limit create and update verbs on environments.fission.io to platform administrators through namespaced RBAC until the upgrade is complete.
bash
# Kyverno policy fragment to block dangerous Fission Environment podSpecs
kubectl get environments.fission.io -A -o json | \
  jq '.items[] | select(.spec.runtime.podSpec.hostPID==true or .spec.runtime.podSpec.hostNetwork==true or .spec.builder.podSpec.hostPID==true) | {ns: .metadata.namespace, name: .metadata.name}'

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypePrivilege Escalation

  • Vendor/TechFission

  • SeverityCRITICAL

  • CVSS Score9.9

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-269
  • Technical References
  • GitHub Pull Request #3390

  • GitHub Pull Request #3391

  • GitHub Release v1.24.0

  • GitHub Security Advisory GHSA-wmgg-3p4h-48x7
  • Related CVEs
  • CVE-2026-50564: Fission Privilege Escalation Vulnerability

  • CVE-2026-50563: Fission Privilege Escalation Vulnerability

  • CVE-2026-46617: Fission Privilege Escalation Vulnerability

  • CVE-2026-49822: Fission Privilege Escalation Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English