CVE-2026-33211 is a critical path traversal vulnerability found in Tekton Pipelines versions 1.0.0 up to 1.10.2 (excluding patched releases). This flaw allows an authenticated tenant to read arbitrary files, such as ServiceAccount tokens, from the resolver pod's filesystem via the pathInRepo parameter. With a CVSS score of 9.6 CRITICAL, it presents a network attack vector requiring low privileges and complexity, leading to high confidentiality and integrity impacts. There is no evidence of active exploitation or public exploit code, though it has received limited community discussion. Remediation involves upgrading to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, or 1.10.2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.1.0, < 1.3.3CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:tekton_pipelines:*:*:*:*:*:go:*:* | ||
>= 1.4.0, < 1.6.1CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:tekton_pipelines:*:*:*:*:*:go:*:* | ||
>= 1.7.0, < 1.9.2CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:tekton_pipelines:*:*:*:*:*:go:*:* | ||
>= 1.10.0, < 1.10.2CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:tekton_pipelines:*:*:*:*:*:go:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:tekton_pipelines:1.0.0:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.