CVE-2026-46617Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, Fission runtime pods were created with ServiceAccountName: fission-fetcher, and the fission-fetcher ServiceAccount was granted namespace-wide get on secrets and configmaps (it needs that to load function code, env vars, and config). The runtime pod's automounted token was reachable from inside the user's function container at /var/run/secrets/kubernetes.io/serviceaccount/token, so user-supplied function code inherited the same Kubernetes API privileges and could read any secret or configmap in the function's namespace — far beyond the Function.spec.secrets allowlist that the function specification suggests. This issue has been patched in version 1.23.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-250CWE-269CWE-538

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-21); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-21: 1Mentions · 2026-06-30: 1Technical Details · 2026-06-30: 105-2106-30
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 Fission Builder Pods, Service #Account Token Exposure, #CVE-2026-46617 (High) -DC-Jun2026-750 https://dailycve.com/fission-builder-pods-service-account-token-exposure-cve-2026-46617-high-dc-jun2026-750/

    Post summary

    The tweet announces the discovery of CVE‑2026‑46617, a high‑severity account token exposure vulnerability in Fission Builder Pods, without providing PoC, exploit, or patch details.

    0000048
    217 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Fission, Privilege Escalation, #CVE-2026-46617 (High) https://dailycve.com/fission-privilege-escalation-cve-2026-46617-high/

    Post summary

    The post announces a high‑severity privilege escalation vulnerability (CVE‑2026‑46617) in Fission, but offers no technical details, proofs of concept, or evidence of exploitation.

    0000049
    207 followersView on X

Explore more