CVE-2026-32613Disclosure(linuxfoundation / spinnaker)

MEDIUMCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch linuxfoundation spinnaker systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring Expression Language) to process information - specifically around expected artifacts. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, unlike orca, it was NOT restricting that context to a set of trusted classes, but allowing FULL JVM access. This enabled a user to use arbitrary java classes which allow deep access to the system. This enabled the ability to invoke commands, access files, etc. Versions 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2 contain a patch. As a workaround, disable echo entirely.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spinnaker

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 13 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 9 signals
  • Disclosure: 7 classified signals
  • Peaked 2d ago at 9 mentions (2026-04-21); latest day: 1
  • 13 total mentions across 3 days

Affected systems

Products
spinnaker

Deep dive

Activity timeline13 mentions / 3d
02579Mentions · 2026-04-21: 9Mentions · 2026-04-22: 3Mentions · 2026-04-23: 1PoC Mentioned / Linked · 2026-04-21: 3PoC Mentioned / Linked · 2026-04-22: 1PoC Mentioned / Linked · 2026-04-23: 1Exploit Tool / Code · 2026-04-23: 1Patch / Workaround · 2026-04-21: 2Technical Details · 2026-04-21: 7Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 104-2104-2204-23
Signal classification4 categories
Disclosure
753.8%
PoC
323.1%
Patch
215.4%
Exploit
17.7%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-04-219
Disclosure5Patch2PoC2
2026-04-223
Disclosure2PoC1
2026-04-231
Exploit1
Full discourse13 posts
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-32604(CVSS 10.0) &CVE-2026-32613(CVSS 10.0): The RCE Flaws Threatening Spinnaker Pipelines. 🧐Detail :https://zeropath.com/blog/spinnaker-rce-production-compromise 📊 2.2K Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Spinnaker%22 👇Query HUNTER : http://product.name="Spinnaker" 📰Refer:https://github.com/spinnaker/spinnaker/security/advisories/GHSA-x3j7-7pgj-h87r https://github.com/spinnaker/spinnaker/security/advisories/GHSA-69rw-45wj-g4v6 https://securityonline.info/spinnaker-critical-rce-clouddriver-echo-vulnerability/ #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post announces two high‑severity RCE CVEs affecting Spinnaker pipelines, providing basic details and links to advisories, but no PoC, exploit code, or mention of active exploitation.

    022043153.9K
    26.0K followersView on X
  • LeftenantZero@LeftenantZero
    Disclosure

    I just published two 10.0 severity Spinnaker vulns that allow code execution and pivoting into source control and production environments! https://zeropath.com/blog/spinnaker-rce-production-compromise (CVE-2026-32604 and CVE-2026-32613) These issues demonstrate the importance of zero trust architectures and defense in depth.

    Post summary

    The author disclosed two 10.0 severity Spinnaker vulnerabilities (CVE-2026-32604 and CVE-2026-32613) that enable code execution and pivoting, with a linked blog post presumably containing further details.

    100169253.0K
    267 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    Spinnaker critical RCEs: CVE-2026-32604 / CVE-2026-32613 (CVSS 9.9) Unauth RCE on clouddriver + full JVM access via SPeL → command execution & file access. CI/CD = direct path to prod.

    Post summary

    The post announces critical unauthenticated RCE vulnerabilities in Spinnaker’s clouddriver component (CVE-2026-32604/CVE-2026-32613) with a high CVSS score and potential for command execution via SPeL.

    100232191.0K
    237 followersView on X
  • ZeroPath@ZeroPathAI
    PoC

    Walkthrough: exploiting ZeroPath's new critical severity Spinnaker vulns for code execution and production environment access. (CVE-2026-32604 and CVE-2026-32613) https://youtu.be/ma-00ggxSp4

    Post summary

    The post announces a YouTube walkthrough demonstrating exploitation of two Spinnaker CVEs for code execution and production access, but does not provide functional code, a patch, or evidence of active exploitation.

    01040341
    251 followersView on X
  • ZeroPath@ZeroPathAI
    PoC

    We've discovered two critical (CVSS 10.0) flaws in the popular Spinnaker continuous delivery platform. Both allow attackers to execute arbitrary code and steal production source control and cloud credentials. MITRE has assigned the vulnerabilities CVE-2026-32604 and CVE-2026-32613. Detailed write up with POCs: https://zeropath.com/blog/spinnaker-rce-production-compromise

    Post summary

    Two new CVE‑2026‑32604 and CVE‑2026‑32613 flaws in Spinnaker are disclosed with CVSS 10.0 and an associated PoC write‑up is provided at Zeropath.

    10010122
    222 followersView on X
  • LeftenantZero@LeftenantZero
    PoC

    @UpwindMDR Here's the blog post where we announced CVE-2026-32604 and CVE-2026-32613. Includes full technical details + working POCs! https://zeropath.com/blog/spinnaker-rce-production-compromise

    Post summary

    The post announces CVE‑2026‑32604 and CVE‑2026‑32613 and asserts that full technical details along with working proof‑of‑concepts are available, though it does not discuss patches, active exploitation or debunking.

    00010162
    273 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32613 Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring Expression Language) to process information - … https://www.cve.org/CVERecord?id=CVE-2026-32613

    Post summary

    The post announces CVE‑2026‑32613 affecting Spinnaker, noting its use of Spring Expression Language, but offers no further technical or patch information.

    10000104
    57.2K followersView on X
  • LeftenantZero@LeftenantZero
    Exploit

    https://youtu.be/ma-00ggxSp4 Hands on video walkthrough: Exploiting the new critical Spinnaker vulns for RCE and credential theft. (CVE-2026-32604 and CVE-2026-32613) Includes POCs and script to stand up your own lab environment

    Post summary

    A YouTube video demonstrates exploitation of two Spinnaker CVEs, providing PoC and script, but does not report real‑world attacks or patches.

    00000170
    273 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: 2 Critical vulnerabilities CVE-2026-32613 & CVE-2026-32604 in Spinnaker Continuous Delivery (CD) platform! #Patch #Patch #Patch

    Post summary

    The tweet announces two critical CVEs in the Spinnaker Continuous Delivery platform but offers no further technical details, PoC, or patch instructions.

    00000182
    7.2K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Spinnaker, RCE via expression parsing due to unrestricted context handling, #CVE-2026-32613 (Critical) https://dailycve.com/spinnaker-rce-via-expression-parsing-due-to-unrestricted-context-handling-cve-2026-32613-critical/

    Post summary

    A critical RCE vulnerability (CVE-2026-32613) in Spinnaker has been disclosed, caused by unrestricted context handling during expression parsing.

    0000041
    183 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32613: Spinnaker vulnerable to RCE via ... SPeL injection with full JVM access in Spinnaker Echo = instant RCE paradise for any authenticated user who can craft a... https://zerodaysignal.com/vulnerability/CVE-2026-32613 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a new RCE vulnerability (CVE-2026-32613) in Spinnaker involving SPeL injection that allows authenticated users to achieve full JVM access.

    0000073
    218 followersView on X
  • Can Artuc@canartuc
    Patch

    Spinnaker shipped CVE-2026-32613 (CVSS 9.9 remote takeover via Spring Expression Language) with back-ports across four release branches. Teams on 2025.x stay on 2025.x. I have shipped this kind of old-branch fix. It is the choice that costs the maintainer most.

    Post summary

    Spinnaker has released patches for the high‑severity CVE‑2026‑32613 remote takeover vulnerability, with backports across multiple release branches.

    0000040
    168 followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: Cloud-native deployments (CVSS 9.8-9.9) Affected: Spinnaker; Doorman; Vvveb; SGLang Internet-facing risks dominate, led by cloud-native deployments and identity/access flaws; fixes and mitigations below. • CVE-2026-32604 (CVSS 9.9) Spinnaker allows remote command execution on clouddriver pods via unauthenticated access; affected versions prior to 2026.1.0, 2026.0.1, 2025.4.2, 2025.3.2. • CVE-2026-32613 (CVSS 9.9) Spinnaker SPeL context allowed full JVM access enabling arbitrary Java class usage to invoke commands and access files; affected versions prior to 2026.1.0, 2026.0.1, 2025.4.2, 2025.3.2. • CVE-2026-30269 (CVSS 9.9) Doorman improper access control allows authenticated users to escalate their own role to non-admin via /platform/user/{username}; affected versions v0.1.0 and v1.0.2. • CVE-2026-39918 (CVSS 9.8) Vvveb installation endpoint vulnerability: the subdir POST parameter is written unsanitized into env.php, enabling unauthenticated remote code execution as the web server user; affected versions prior to 1.0.8.1. • CVE-2026-5760 (CVSS 9.8) SGLang reranking endpoint /v1/rerank enables remote code execution when a model file contains a malicious http://tokenizer.chat_template; affects SGLang prior to 0.5.9. 🛠️ Action - Patch/upgrade to fixed versions called out (Spinnaker 2026.1.0+; Doorman latest; Vvveb 1.0.8.1+; SGLang 0.5.9+). - Prioritize internet-facing instances and edge appliances first. - If mitigation is needed, apply available mitigations and reduce exposure where fixes are not yet deployed. - Add detections for exploitation patterns (unauthenticated RCE attempts, suspicious file-write paths, unexpected process spawns). - Hunt for indicators around affected services during disclosure-to-now window (logs, EDR, WAF). - Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post announces critical cloud‑native CVEs with technical details and delivers patch/up‑grade guidance, without indicating exploitation or false‑positive claims.

    0000095
    99 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationspinnaker---

Explore more