Spinnaker Echo, an open-source multi-cloud continuous delivery service, contains a critical remote code execution vulnerability in versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2. The flaw stems from insufficient input validation in the Spring Expression Language (SPeL) processor used for handling expected artifacts. Unlike the Orca service, Echo fails to restrict SPeL context to trusted classes, allowing authenticated users to access arbitrary Java classes and execute system commands, read files, and achieve deep system compromise. The vulnerability presents a CRITICAL severity rating with a CVSS v3.1 score of 9.9. It requires only low attack complexity and low privileges to exploit, but can be executed remotely over the network without user interaction. The attack scope is changed, meaning the impact extends beyond the vulnerable component to affect the confidentiality, integrity, and availability of the entire system. Currently, there is no evidence of active exploitation in the wild, nor is this vulnerability listed on the Known Exploited Vulnerabilities (KEV) catalog. However, given the straightforward attack vector and high severity, organizations should prioritize patching to the fixed versions. A temporary workaround exists through disabling Echo entirely, though this may impact operational capabilities. The vulnerability warrants immediate attention despite the low current EPSS score and lack of public exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2025.3.2CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:* | ||
>= 2025.4.0, < 2025.4.2CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:* | ||
>= 2026.0.0, < 2026.0.1CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:spinnaker:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.