CVE-2026-40923Disclosure(linuxfoundation / tekton_pipelines)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, a validation bypass in the VolumeMount path restriction allows mounting volumes under restricted /tekton/ internal paths by using .. path traversal components. The restriction check uses strings.HasPrefix without filepath.Clean, so a path like /tekton/home/../results passes validation but resolves to /tekton/results at runtime. Versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1 fix the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tekton_pipelines

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-26); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
tekton_pipelines

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-26: 2Mentions · 2026-04-28: 1Technical Details · 2026-04-26: 2Technical Details · 2026-04-28: 104-2604-28
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-262
Disclosure2
2026-04-281
Disclosure1
Full discourse3 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-40923: CVE-2026-40923: Tekton Pipelines VolumeMount Path Restriction Bypass via Missing Path Normalization CVE-2026-40923 is a path traversal vulnerability in Tekton Pipelines, a Kubernetes-native CI/CD framework. The vulnerability allows an ... https://cvereports.com/reports/CVE-2026-40923

    Post summary

    A path traversal vulnerability (CVE‑2026‑40923) has been disclosed in Tekton Pipelines, allowing attackers to bypass volume‑mount path restrictions through missing path normalization. No PoC, exploit, or patch is mentioned in the text.

    0000028
    36 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40923 Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Prior to 1.11.1, a validation bypass in the VolumeMount path restriction al… https://www.cve.org/CVERecord?id=CVE-2026-40923 ----- Traducción: CVE-2026-40923 Tek… http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-40923 in Tekton Pipelines, noting a validation bypass in VolumeMount path restriction prior to v1.11.1, but provides no further details on exploitation, patches, or PoC.

    0000033
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40923 Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Prior to 1.11.1, a validation bypass in the VolumeMount path restriction al… https://www.cve.org/CVERecord?id=CVE-2026-40923

    Post summary

    The tweet announces CVE‑2026‑40923, noting a validation bypass in Tekton Pipelines’ VolumeMount path restriction prior to version 1.11.1, but gives no further technical details, PoC, patch, or evidence of exploitation.

    00000189
    57.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationtekton_pipelines-go-

Explore more