CVE-2026-32604: Spinnaker vulnerable to RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
Impact A bad actor can execute arbitrary commands very simply on the clouddriver pods. This can expose credentials, remove files, or inject resources easily.
Workarounds Disable the gitrepo artifact types.
Other sources
Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands very simply on the clouddriver pods. This can expose credentials, remove files, or inject resources easily. Versions 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2 contain a patch. As a workaround, disable the gitrepo artifact types.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32604?
CVE-2026-32604 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-32604?
To mitigate CVE-2026-32604, upgrade to Spinnaker versions 2026.1.0, 2026.0.1, 2025.4.2, or 2025.3.2.
What type of vulnerability is CVE-2026-32604?
CVE-2026-32604 is a remote code execution vulnerability caused by improper sanitization of user input.
Which versions of Spinnaker are affected by CVE-2026-32604?
CVE-2026-32604 affects Spinnaker versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2.
What can attackers do with CVE-2026-32604?
An attacker can exploit CVE-2026-32604 to execute arbitrary commands on the server by manipulating git repository inputs.