OVERVIEW CVE-2026-32604 is a critical vulnerability in Spinnaker, an open source multi-cloud continuous delivery platform. Affected versions include all releases prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2. The vulnerability allows unauthorized actors to execute arbitrary commands on clouddriver pods, potentially exposing credentials, deleting files, or injecting malicious resources into the deployment infrastructure. SEVERITY This vulnerability carries a CVSS score of 9.9 (Critical) with a network-based attack vector requiring only low privileges and no user interaction. The attack complexity is low, meaning exploitation is straightforward. The impact is severe across all security dimensions: confidentiality, integrity, and availability are all rated as high. This reflects the ability to gain complete control over affected clouddriver components and the wider Spinnaker environment. EXPLOITATION STATUS There is no current evidence of active exploitation in the wild, as indicated by its absence from the Known Exploited Vulnerabilities (KEV) catalog and inactive Hot List status. The EPSS score of 0.0007 suggests minimal current exploitation probability relative to other CVEs. However, organizations should prioritize patching immediately given the ease of exploitation and severity, as the straightforward nature of the attack vector means weaponization risk remains significant. A workaround exists by disabling gitrepo artifact types pending patch deployment.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2025.3.2CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:* | ||
>= 2025.4.0, < 2025.4.2CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:* | ||
>= 2026.0.0, < 2026.0.1CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.