Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32613

36
FAUCET Score

Spinnaker Echo, an open-source multi-cloud continuous delivery service, contains a critical remote code execution vulnerability in versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2. The flaw stems from insufficient input validation in the Spring Expression Language (SPeL) processor used for handling expected artifacts. Unlike the Orca service, Echo fails to restrict SPeL context to trusted classes, allowing authenticated users to access arbitrary Java classes and execute system commands, read files, and achieve deep system compromise. The vulnerability presents a CRITICAL severity rating with a CVSS v3.1 score of 9.9. It requires only low attack complexity and low privileges to exploit, but can be executed remotely over the network without user interaction. The attack scope is changed, meaning the impact extends beyond the vulnerable component to affect the confidentiality, integrity, and availability of the entire system. Currently, there is no evidence of active exploitation in the wild, nor is this vulnerability listed on the Known Exploited Vulnerabilities (KEV) catalog. However, given the straightforward attack vector and high severity, organizations should prioritize patching to the fixed versions. A temporary workaround exists through disabling Echo entirely, though this may impact operational capabilities. The vulnerability warrants immediate attention despite the low current EPSS score and lack of public exploit code.

Impacted Technologies

VendorProductVersion(s)CPE
< 2025.3.2CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:*
>= 2025.4.0, < 2025.4.2CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:*
>= 2026.0.0, < 2026.0.1CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.9CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.1
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.55%
Probability of exploitation in next 30 days
EPSS Percentile
42.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0055 is in the 45th percentile among its peer group of 1,124 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

mavenpatch availablevia ghsa
Product: io.spinnaker.echo:echo-pipelinetriggersFixed in: 2026.0.1
mavenpatch availablevia ghsa
Product: io.spinnaker.echo:echo-pipelinetriggersFixed in: 2025.4.2
mavenpatch availablevia ghsa
Product: io.spinnaker.echo:echo-pipelinetriggersFixed in: 2025.3.2

Vendor Advisories (1)

mavenGHSA-69rw-45wj-g4v6critical

Spinnaker: RCE via expression parsing due to unrestricted context handling

Apr 21, 2026

References

zeropath.com / blog/spinnaker-rce-production-compromise
github.com / spinnaker/spinnaker/releases/tag/spinnaker-release-2025.3.2
ProductRelease Notes
github.com / spinnaker/spinnaker/releases/tag/spinnaker-release-2025.4.2
ProductRelease Notes
github.com / spinnaker/spinnaker/releases/tag/spinnaker-release-2026.0.1
ProductRelease Notes
github.com / spinnaker/spinnaker/security/advisories/GHSA-69rw-45wj-g4v6
MitigationVendor Advisory