Executive brief
Codefresh is a CI/CD platform used to automate software build and deployment processes. An authenticated user can abuse an API endpoint to escalate their privileges to Admin level, gaining full control over the platform and potentially compromising all pipelines, credentials, and deployment configurations. This bypasses access controls that would normally restrict such permissions to designated administrators.
Technical details
The vulnerability is a privilege escalation flaw in the Codefresh API that allows an authenticated user to elevate their permissions to Admin level without proper authorization checks. The root cause lies in insufficient validation of privilege-escalation requests on a specific API endpoint. Attack preconditions require valid user authentication; no additional network positioning or user interaction is needed. An attacker with any valid account can exploit this to gain administrative access and fully compromise the platform. The vulnerability affects Codefresh 2.x versions before 2.11.15; patched versions 2.11.15 and later contain a fix that properly validates privilege-escalation requests.
Affected products
- Codefresh Codefresh 2.x.x before 2.11.15
Timeline
- 2026-06-11: disclosed: Discovery date
- 2026-06-12: patched: Patch release date
- 2026-08-20: advisory: Advisory release date