Junglewise Threat Intelligence

CVE-2026-49821: Fission cross-namespace auth bypass in buildermgr controller

CVE-2026-49821 · Severity: high · CVSS 7.7 · Published 2026-06-10

Technologies: Fission, github.com/fission/fission (Go). Vendors: Fission, Go.

Executive brief

Fission is a framework for running serverless functions on Kubernetes. A security flaw in the build manager allows a user in one project (namespace) to execute code in another project's build environment. This could allow an attacker to steal sensitive credentials and access private data, such as secrets and configuration files, belonging to other teams or customers.

Technical details

The Fission buildermgr controller fails to validate that the namespace specified in a Package's environment reference (Package.spec.environment.namespace) matches the Package's own metadata namespace. An attacker with permissions to create Packages in their own namespace can reference an Environment in a victim's namespace. The controller, using its high-privilege service account, then dispatches build commands into the victim's builder pod. By using build lifecycle hooks (like npm preinstall), an attacker can execute arbitrary code to exfiltrate the 'fission-builder' service account token from the victim's pod via build logs, subsequently gaining read access to all Secrets and ConfigMaps in the victim's namespace. This is a 'Confused Deputy' vulnerability (CWE-441). The issue is fixed in v1.24.0 by adding namespace validation in both the admission webhook and the controller.

Affected products

  • Fission Fission <= 1.23.0

Timeline

  • 2026-05-26: disclosed: Initial disclosure to vendor
  • 2026-06-10: advisory: NVD publication date
  • 2026-06-30: patched: GitHub Advisory published and fix confirmed in v1.24.0

References

Related threats