Junglewise Threat Intelligence

CVE-2026-49824: Fission improper authorization via cross-namespace environment references

CVE-2026-49824 · Severity: high · CVSS 8.5 · Published 2026-06-10

Technologies: Fission, github.com/fission/fission (Go). Vendors: Fission, Go.

Executive brief

Fission is a framework for running serverless functions on Kubernetes. A security flaw allowed users to run their own code inside the software environments belonging to other users or departments. This could lead to the theft of sensitive data, such as hardcoded passwords or proprietary code, and allow an attacker to bypass security boundaries between different teams.

Technical details

The Fission Function admission webhook in `pkg/webhook/function.go` failed to validate the `spec.environment.namespace` field, despite correctly validating secrets and configmaps. An attacker with `functions.fission.io/create` permissions in their own namespace could specify a victim's namespace in the environment reference. When the `poolmgr` or `newdeploy` components schedule the function, they pull the victim's Environment CRD, causing the attacker's code to execute within the victim's container image. This facilitates credential theft from environment variables/images and confused-deputy attacks. The fix in v1.24.0 introduces validation in the webhook and redundant checks in the controller to prevent bypasses.

Affected products

  • Fission Fission <= 1.23.0

Timeline

  • 2026-05-26: disclosed
  • 2026-06-10: advisory: NVD publication
  • 2026-06-30: advisory: GitHub Advisory published

References

Related threats