Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32604

36
FAUCET Score

OVERVIEW CVE-2026-32604 is a critical vulnerability in Spinnaker, an open source multi-cloud continuous delivery platform. Affected versions include all releases prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2. The vulnerability allows unauthorized actors to execute arbitrary commands on clouddriver pods, potentially exposing credentials, deleting files, or injecting malicious resources into the deployment infrastructure. SEVERITY This vulnerability carries a CVSS score of 9.9 (Critical) with a network-based attack vector requiring only low privileges and no user interaction. The attack complexity is low, meaning exploitation is straightforward. The impact is severe across all security dimensions: confidentiality, integrity, and availability are all rated as high. This reflects the ability to gain complete control over affected clouddriver components and the wider Spinnaker environment. EXPLOITATION STATUS There is no current evidence of active exploitation in the wild, as indicated by its absence from the Known Exploited Vulnerabilities (KEV) catalog and inactive Hot List status. The EPSS score of 0.0007 suggests minimal current exploitation probability relative to other CVEs. However, organizations should prioritize patching immediately given the ease of exploitation and severity, as the straightforward nature of the attack vector means weaponization risk remains significant. A workaround exists by disabling gitrepo artifact types pending patch deployment.

Impacted Technologies

VendorProductVersion(s)CPE
< 2025.3.2CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:*
>= 2025.4.0, < 2025.4.2CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:*
>= 2026.0.0, < 2026.0.1CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.9CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.1
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.61%
Probability of exploitation in next 30 days
EPSS Percentile
45.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0061 is in the 48th percentile among its peer group of 1,124 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

mavenpatch availablevia ghsa
Product: io.spinnaker.clouddriver:clouddriver-artifacts-gitrepoFixed in: 2026.0.1

Vendor Advisories (1)

mavenGHSA-x3j7-7pgj-h87rcritical

Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths

Apr 21, 2026

References

zeropath.com / blog/spinnaker-rce-production-compromise
github.com / spinnaker/spinnaker/releases/tag/spinnaker-release-2025.3.2
ProductRelease Notes
github.com / spinnaker/spinnaker/releases/tag/spinnaker-release-2025.4.2
ProductRelease Notes
github.com / spinnaker/spinnaker/releases/tag/spinnaker-release-2026.0.1
ProductRelease Notes
github.com / spinnaker/spinnaker/security/advisories/GHSA-x3j7-7pgj-h87r
MitigationVendor Advisory