A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-50569

CVE-2026-50569: Fission Auth Bypass Vulnerability

CVE-2026-50569 is an authentication bypass flaw in Fission, a Kubernetes-native serverless framework, allowing attackers to bypass URL validation checks. This post covers technical details, affected versions, impact, and mitigation.

Published: June 11, 2026

CVE-2026-50569 Overview

CVE-2026-50569 is an input validation flaw [CWE-20] in Fission, an open-source Kubernetes-native serverless framework. Versions prior to 1.25.0 fail to validate the RelativeURL and Prefix fields of HTTPTriggerSpec at the API server layer. The HTTPTriggerSpec.Validate() function checks Methods, FunctionReference, Host, IngressConfig, and CorsConfig but silently skips URL fields. Validation exists only in the CLI at pkg/fission-cli/cmd/httptrigger/create.go:83. Authenticated users who create HTTPTriggers via kubectl apply or direct Kubernetes REST API calls bypass all URL-level checks. The issue is patched in version 1.25.0.

Critical Impact

Authenticated Kubernetes users can create Fission HTTPTriggers with malformed RelativeURL or Prefix values, bypassing server-side validation and impacting routing integrity.

Affected Products

  • Fission serverless framework versions prior to 1.25.0
  • Kubernetes clusters running Fission with HTTPTrigger CRDs
  • Deployments relying on API-server CEL validation for HTTPTrigger inputs

Discovery Timeline

  • 2026-06-10 - CVE-2026-50569 published to NVD
  • 2026-06-10 - Last updated in NVD database

Technical Details for CVE-2026-50569

Vulnerability Analysis

The vulnerability resides in Fission's HTTPTrigger validation pipeline. The server-side HTTPTriggerSpec.Validate() function performs checks on multiple fields but omits validation for RelativeURL and Prefix. These two URL-routing fields define how incoming HTTP requests map to backend Fission functions.

Fission previously relied on a CRD admission webhook to enforce HTTPTrigger validation. After post-CRD modernization, the project replaced the webhook with Common Expression Language (CEL) rules at the Kubernetes API server. The migration did not port any rules covering RelativeURL or Prefix, leaving both fields unchecked at every server-side boundary.

The Fission command-line interface enforces URL validation at pkg/fission-cli/cmd/httptrigger/create.go:83. However, this check executes only when users create triggers through the official CLI. Requests submitted through kubectl apply or any direct call to the Kubernetes REST API bypass the CLI entirely. The CVSS vector indicates an authenticated, network-accessible flaw with limited integrity impact.

Root Cause

The root cause is incomplete migration of validation logic. Field-level checks that previously ran in the admission webhook were not reimplemented in CEL after CRD modernization. The Validate() function silently returns success for RelativeURL and Prefix instead of rejecting unsupported values. Defense-in-depth was broken because client-side and server-side validation no longer cover the same field set.

Attack Vector

An authenticated user with permission to create HTTPTrigger custom resources submits a manifest with crafted RelativeURL or Prefix values directly to the Kubernetes API. The API server accepts the resource, and Fission's router consumes the unvalidated configuration. The attack does not require elevated cluster privileges beyond standard HTTPTrigger create rights. See the GitHub Security Advisory GHSA-vchh-r53j-8mpw for additional context.

Detection Methods for CVE-2026-50569

Indicators of Compromise

  • HTTPTrigger custom resources containing RelativeURL or Prefix values that do not conform to expected URL syntax
  • Audit log entries showing HTTPTrigger creation via kubectl apply or REST API calls that bypass the Fission CLI
  • Unexpected routing behavior or 404 responses in the Fission router for routes that appear valid in the CRD

Detection Strategies

  • Inspect existing HTTPTrigger objects in the cluster and compare RelativeURL and Prefix fields against the validation logic in pkg/fission-cli/cmd/httptrigger/create.go:83
  • Enable Kubernetes audit logging for the fission.io/v1 API group and alert on HTTPTrigger create or update events not originating from the Fission CLI user agent
  • Run Fission's installed version check and flag any cluster running a release earlier than 1.25.0

Monitoring Recommendations

  • Forward Kubernetes API server audit logs to a centralized analytics platform for continuous review of HTTPTrigger mutations
  • Track Fission router error rates and correlate spikes with recent HTTPTrigger create or update events
  • Add policy checks in admission controllers such as Kyverno or OPA Gatekeeper to validate RelativeURL and Prefix formats independently

How to Mitigate CVE-2026-50569

Immediate Actions Required

  • Upgrade Fission to version 1.25.0 or later, which restores server-side validation for RelativeURL and Prefix
  • Audit all existing HTTPTrigger resources and remove or correct entries with malformed URL fields
  • Restrict create and update permissions on HTTPTrigger CRDs to trusted service accounts and users via Kubernetes RBAC

Patch Information

The Fission maintainers fixed the issue in Fission release v1.25.0. The corresponding code change is in GitHub Pull Request #3464, which adds the missing validation for RelativeURL and Prefix to HTTPTriggerSpec.Validate().

Workarounds

  • Deploy an admission policy in Kyverno or OPA Gatekeeper that enforces URL syntax rules on HTTPTrigger RelativeURL and Prefix fields
  • Limit HTTPTrigger creation to the Fission CLI by removing direct CRD write permissions for non-administrative roles
  • Implement a CI pipeline check that lints Fission manifests against expected URL formats before applying them to the cluster
bash
# Configuration example: upgrade Fission via Helm
helm repo update
helm upgrade --install fission fission-charts/fission-all \
  --namespace fission \
  --version 1.25.0

# Verify the running version
kubectl -n fission get deploy -o jsonpath='{.items[*].spec.template.spec.containers[*].image}'

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeAuth Bypass

  • Vendor/TechFission

  • SeverityMEDIUM

  • CVSS Score4.3

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityNone
  • CWE References
  • CWE-20
  • Technical References
  • GitHub Pull Request

  • GitHub Release v1.25.0

  • GitHub Security Advisory GHSA-vchh-r53j-8mpw
  • Related CVEs
  • CVE-2026-46614: Fission Auth Bypass Vulnerability

  • CVE-2026-46612: Fission Auth Bypass Vulnerability

  • CVE-2026-49821: Fission Auth Bypass Vulnerability

  • CVE-2026-49824: Fission Auth Bypass Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English