CVE-2026-32604Disclosure(linuxfoundation / spinnaker)

HIGHCVSS 9.9 · CRITICAL

Exploitation observed; activity peaked at 9 mentions and remains active

Immediate actions

  • Patch linuxfoundation spinnaker systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands very simply on the clouddriver pods. This can expose credentials, remove files, or inject resources easily. Versions 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2 contain a patch. As a workaround, disable the gitrepo artifact types.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spinnaker

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 18 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 13 signals
  • Disclosure: 11 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 9 mentions (2026-04-21); latest day: 2
  • 18 total mentions across 5 days

Affected systems

Products
spinnaker

Deep dive

Activity timeline18 mentions / 5d
02579Mentions · 2026-04-21: 9Mentions · 2026-04-22: 5Mentions · 2026-04-23: 1Mentions · 2026-07-17: 1Mentions · 2026-09-19: 2PoC Mentioned / Linked · 2026-04-21: 3PoC Mentioned / Linked · 2026-04-22: 2PoC Mentioned / Linked · 2026-04-23: 1PoC Mentioned / Linked · 2026-09-19: 1Exploit Tool / Code · 2026-04-21: 1Exploit Tool / Code · 2026-04-23: 1Exploit Tool / Code · 2026-07-17: 1Exploit Tool / Code · 2026-09-19: 1Active Exploitation · 2026-07-17: 1Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-04-22: 3Technical Details · 2026-04-21: 9Technical Details · 2026-04-22: 3Technical Details · 2026-07-17: 104-2104-2204-2307-1709-19
Signal classification6 categories
Disclosure
1161.1%
General
211.1%
PoC
211.1%
Patch
15.6%
Active Exploitation
15.6%
Exploit
15.6%
Referenced assets19 URLs
Classification over time
DateTotalLabels
2026-04-219
Disclosure7General1Patch1
2026-04-225
Disclosure4PoC1
2026-04-231
PoC1
2026-07-171
Active Exploitation1
2026-09-192
Exploit1General1
Full discourse18 posts
  • Yusuf Can Çakır@Yusufcancakiir
    Active Exploitation

    Found an open directory hosting a layered financial fraud operation across three simultaneous tracks: a Magecart-style card skimmer chain, a mass CVE exploitation framework, and a trojan distributed through Chinese streaming software packaging. All of it feeding the same PII collection pipeline. The skimmer track starts with FOFA. The actor runs automated queries targeting WooCommerce, Magento, and Stripe-integrated checkout pages, sorting results into structured target lists by category: builder_woo_checkout, stripe_woo_checkout, magento_checkout, checkout_cdn_js. Output lands in pii_consolidated.csv, with a second batch file visible alongside it. This has been running in passes. The skimmer component is a WooCommerce and Stripe-targeted Magecart payload. Injection engine supports page-level download, mitmproxy transparent proxy, and browser console delivery. C2 receiver runs on the same host. Target profile: Stripe Elements checkout pages, WooCommerce wc-ajax endpoints. The exploitation track runs in parallel. poc_scanner.py drives 300 concurrent probes against FOFA-sourced targets through a three-stage pipeline: liveness check, service fingerprinting, then PoC verification. CVEs being actively weaponized: CVE-2026-21858 — n8n unauthenticated RCE, CVSS 10.0 CVE-2026-6815 — Casdoor path traversal to RCE, CVSS 9.8 CVE-2026-32604 — Spinnaker shell injection, CVSS 10.0 CVE-2026-34486 — Tomcat Tribes auth bypass to RCE, CVSS 9.8 CVE-2026-25212 — Percona PMM RCE, CVSS 9.9 CVE-2026-35273 — PeopleSoft unauthenticated SSRF to RCE, CVSS 9.8 CVE-2026-23744 — MCPJam Inspector unauthenticated RCE, CVSS 9.8 CVE-2026-42167 — ProFTPD CVE-2026-6182 — SQL injection auth bypass CVE-2025-24587, CVE-2025-4396 A separate WordPress track runs alongside: mass SQL injection via wp_sqli_mass.py, aggressive dump via wp_aggressive_dump.py, PhpMyAdmin brute-force against the same pool. The trojan track is socially engineered. 直播助手化.v2.exe presents as a legitimate Chinese streaming helper application. VMProtect 3.2–3.5 wrapping. 29/70 on VirusTotal at time of analysis. Family: flystudio, chinad, dlii. It ships with HPSocket4C.dll, pb.dll, pb64.dll, and gzip.dll as side-loaded components. The infection surface is Chinese-speaking streaming users who would recognize the product name as familiar tooling. C2 routes through v2ray. Two license spoofing servers complete the toolkit. bypass_server.py impersonates http://premium.dotbypasser.workers.dev, handling RSA-OAEP encrypted license exchange and returning forged validation responses with 10-year expiry timestamps. fake_auth_server.py covers a separate streaming platform, impersonating http://api.vmks.cn and related domains, returning fake authorization tokens. Both appear to serve tooling distribution rather than direct victim infrastructure. One additional finding on the C2 host: evidence of AI-assisted offensive operations. A DeepSeek API configuration points to http://api.deepseek.com through an Anthropic-compatible interface, and a structured offensive security framework containing 70+ purpose-built skill modules for vulnerability classes including SQLi, XSS, SSRF, RCE, IDOR, OAuth, SAML, cloud misconfiguration, Kubernetes, CI/CD, M365/Entra, VMware vCenter, and supply chain recon. The actor is running systematized, AI-assisted attack methodology. This pattern is increasingly documented across financially motivated operations. OPSEC failure on an otherwise capable operator. filter_cn.py is on the box and actively used. It strips Chinese IP ranges from FOFA output sets before exploitation runs begin. The actor is deliberately skipping domestic targets, a consistent behavioral marker across Chinese financially motivated operations. Additionally, the FOFA API credential is hardcoded in cleartext across the client scripts. Easy attribution anchor.

    Post summary

    The text describes an operational threat group actively weaponizing multiple high‑severity CVEs within a multi‑track fraud operation, offering and running custom exploit scripts across various platforms.

    215054404.8K
    1.6K followersView on X
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-32604(CVSS 10.0) &CVE-2026-32613(CVSS 10.0): The RCE Flaws Threatening Spinnaker Pipelines. 🧐Detail :https://zeropath.com/blog/spinnaker-rce-production-compromise 📊 2.2K Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Spinnaker%22 👇Query HUNTER : http://product.name="Spinnaker" 📰Refer:https://github.com/spinnaker/spinnaker/security/advisories/GHSA-x3j7-7pgj-h87r https://github.com/spinnaker/spinnaker/security/advisories/GHSA-69rw-45wj-g4v6 https://securityonline.info/spinnaker-critical-rce-clouddriver-echo-vulnerability/ #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post alerts to two high‑scoring RCE vulnerabilities in Spinnaker Pipelines, linking to detailed advisories and a blog that likely contains more technical information. No exploit code or proof of concept is presented, but patch information is referenced.

    022043153.9K
    26.0K followersView on X
  • LeftenantZero@LeftenantZero
    Disclosure

    I just published two 10.0 severity Spinnaker vulns that allow code execution and pivoting into source control and production environments! https://zeropath.com/blog/spinnaker-rce-production-compromise (CVE-2026-32604 and CVE-2026-32613) These issues demonstrate the importance of zero trust architectures and defense in depth.

    Post summary

    The author announced two severe Spinnaker vulnerabilities (CVE-2026-32604 and CVE-2026-32613) that allow code execution and pivoting into source control and production environments.

    100169253.0K
    267 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    Spinnaker critical RCEs: CVE-2026-32604 / CVE-2026-32613 (CVSS 9.9) Unauth RCE on clouddriver + full JVM access via SPeL → command execution & file access. CI/CD = direct path to prod.

    Post summary

    The text announces high‑severity RCE vulnerabilities (CVE‑2026‑32604/32613) in Spinnaker’s clouddriver, highlighting full JVM access via SPeL but lacks details on patches, exploits, or real‑world usage.

    100232191.0K
    237 followersView on X
  • ZeroPath@ZeroPathAI
    PoC

    Walkthrough: exploiting ZeroPath's new critical severity Spinnaker vulns for code execution and production environment access. (CVE-2026-32604 and CVE-2026-32613) https://youtu.be/ma-00ggxSp4

    Post summary

    The post advertises a YouTube walkthrough that demonstrates exploitation of two new critical Spinnaker CVEs to achieve code execution and production environment access.

    01040341
    251 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily Threat Digest Critical Exploits disclosed today: CVE-2021-44228 CVE-2025-24813 CVE-2025-32433 CVE-2026-32604 CVE-2024-30804 ..🧵👇

    Post summary

    The tweet merely lists several CVE identifiers without providing any details about PoC, exploit tools, active exploitation, patches, or technical vulnerability information.

    1101088
    50 followersView on X
  • ZeroPath@ZeroPathAI
    Disclosure

    We've discovered two critical (CVSS 10.0) flaws in the popular Spinnaker continuous delivery platform. Both allow attackers to execute arbitrary code and steal production source control and cloud credentials. MITRE has assigned the vulnerabilities CVE-2026-32604 and CVE-2026-32613. Detailed write up with POCs: https://zeropath.com/blog/spinnaker-rce-production-compromise

    Post summary

    Two critical CVEs were discovered in the Spinnaker platform, accompanied by a PoC link and high‑severity technical details, but no active exploitation, patch information, or mitigation steps are provided.

    10010122
    222 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] CVE-2026-32604 [CRITICAL/PoC] CVE-2026-32604 🔗 https://exploitgrid.net/exploits/93ba6285-bc31-42a3-9b0d-c2521d08ce32

    Post summary

    The post explicitly tags CVE-2026-32604 as an '[EXPLOIT]' and '[CRITICAL/PoC]', linking directly to an exploit repository (exploitgrid.net), indicating the primary purpose is to announce the availability of functional exploit code.

    1000064
    50 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical RCE vulnerability (CVE-2026-32604) in Spinnaker affects gitrepo artifact processing due to improper input sanitization. Exercise caution with untrusted artifact definitions. #Spinnaker #RCE #CloudNative https://www.pulsepatch.io/posts/cve-2026-32604-spinnaker-rce

    Post summary

    The tweet announces a critical RCE CVE‑2026‑32604 in Spinnaker’s gitrepo artifact handling due to improper input sanitization and advises users to be cautious with untrusted artifact definitions.

    0000176
    12 followersView on X
  • LeftenantZero@LeftenantZero
    Disclosure

    @UpwindMDR Here's the blog post where we announced CVE-2026-32604 and CVE-2026-32613. Includes full technical details + working POCs! https://zeropath.com/blog/spinnaker-rce-production-compromise

    Post summary

    The blog post publicly announces CVE-2026-32604 and CVE-2026-32613, providing full technical details and working proof‑of‑concept code.

    00010162
    273 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32604: Spinnaker vulnerable to RCE when... Perfect 10.0 CVSS RCE in Spinnaker's gitrepo artifacts - trivial command injection through unsanitized branch/path para... https://zerodaysignal.com/vulnerability/CVE-2026-32604 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    Spinnaker’s gitrepo artifacts expose a CVSS 10.0 RCE through unsanitized branch/path parameters, with no indication of exploitation or patching yet.

    1000069
    218 followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-41329 | CVSS 9.9 🔴 CVE-2026-30269 | CVSS 9.9 🔴 CVE-2026-32604 | CVSS 9.9 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post highlights three CVEs with high CVSS scores and links to a resource, but offers no details on exploitation, patches, or false positives.

    0001058
    5.6K followersView on X
  • LeftenantZero@LeftenantZero
    PoC

    https://youtu.be/ma-00ggxSp4 Hands on video walkthrough: Exploiting the new critical Spinnaker vulns for RCE and credential theft. (CVE-2026-32604 and CVE-2026-32613) Includes POCs and script to stand up your own lab environment

    Post summary

    The YouTube video walks through exploitation of CVE‑2026‑32604 and CVE‑2026‑32613, offering PoCs and scripts for setting up a lab environment.

    00000170
    273 followersView on X
  • Rapid Risk Radar@rapidriskradar
    Disclosure

    🚨Spinnaker clouddriver RCE — CVE-2026-32604: Critical RCE in clouddriver pods (CVSS 10). PoC available. Patch ASAP; if not possible, disable gitrepo artifact types, rotate cloud creds, isolate clouddriver & audit for compromise. 👉 https://app.rapidriskradar.com/cve/CVE-2026-32604 https://t.co/hfNvmhoTHi

    Post summary

    Spinnaker's clouddriver pods suffer a critical RCE (CVE‑2026‑32604, CVSS 10) with a PoC available; patching or default mitigations are advised.

    00000176
    16 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: 2 Critical vulnerabilities CVE-2026-32613 & CVE-2026-32604 in Spinnaker Continuous Delivery (CD) platform! #Patch #Patch #Patch

    Post summary

    The tweet warns of two newly disclosed critical vulnerabilities affecting Spinnaker's Continuous Delivery platform, but offers no further technical detail, exploit code, or patch information.

    00000182
    7.2K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Spinnaker, RCE via gitrepo artifact injection, #CVE-2026-32604 (Critical) https://dailycve.com/spinnaker-rce-via-gitrepo-artifact-injection-cve-2026-32604-critical/

    Post summary

    The article announces a critical RCE vulnerability (CVE‑2026‑32604) in Spinnaker via gitrepo artifact injection, but it offers only high‑level details without PoC or mitigation information.

    0000038
    183 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32604 Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitr… https://www.cve.org/CVERecord?id=CVE-2026-32604

    Post summary

    The post announces CVE-2026-32604, noting that older Spinnaker releases allow arbitrary code execution, but provides no PoC, exploit, or patch information, and does not indicate active exploitation.

    0000095
    57.2K followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: Cloud-native deployments (CVSS 9.8-9.9) Affected: Spinnaker; Doorman; Vvveb; SGLang Internet-facing risks dominate, led by cloud-native deployments and identity/access flaws; fixes and mitigations below. • CVE-2026-32604 (CVSS 9.9) Spinnaker allows remote command execution on clouddriver pods via unauthenticated access; affected versions prior to 2026.1.0, 2026.0.1, 2025.4.2, 2025.3.2. • CVE-2026-32613 (CVSS 9.9) Spinnaker SPeL context allowed full JVM access enabling arbitrary Java class usage to invoke commands and access files; affected versions prior to 2026.1.0, 2026.0.1, 2025.4.2, 2025.3.2. • CVE-2026-30269 (CVSS 9.9) Doorman improper access control allows authenticated users to escalate their own role to non-admin via /platform/user/{username}; affected versions v0.1.0 and v1.0.2. • CVE-2026-39918 (CVSS 9.8) Vvveb installation endpoint vulnerability: the subdir POST parameter is written unsanitized into env.php, enabling unauthenticated remote code execution as the web server user; affected versions prior to 1.0.8.1. • CVE-2026-5760 (CVSS 9.8) SGLang reranking endpoint /v1/rerank enables remote code execution when a model file contains a malicious http://tokenizer.chat_template; affects SGLang prior to 0.5.9. 🛠️ Action - Patch/upgrade to fixed versions called out (Spinnaker 2026.1.0+; Doorman latest; Vvveb 1.0.8.1+; SGLang 0.5.9+). - Prioritize internet-facing instances and edge appliances first. - If mitigation is needed, apply available mitigations and reduce exposure where fixes are not yet deployed. - Add detections for exploitation patterns (unauthenticated RCE attempts, suspicious file-write paths, unexpected process spawns). - Hunt for indicators around affected services during disclosure-to-now window (logs, EDR, WAF). - Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post announces multiple high‑severity CVEs, details their technical impact, and offers specific patch versions and remediation instructions.

    0000095
    99 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationspinnaker---

Explore more