Vulnary
← back to the feed
Critical· 9.6official fix available

CVE-2026-33211

Tekton Pipelines versions 1.0.0 up to several fixed releases contain a critical path-traversal flaw in the git resolver. A user with permission to create ResolutionRequests can read arbitrary files from the resolver pod, including sensitive ServiceAccount tokens. Patched versions are available and should be applied.

publishedMar 24, 2026
last modifiedAug 3, 2026
sourcesNVD
severity · cvss
9.6
critical · how bad it is
exploitation · epss
<1%
44th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 19, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Any organization running Tekton Pipelines versions 1.0.0 through the unpatched releases listed (before 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2) and allowing tenants to create ResolutionRequests via TaskRuns or PipelineRuns with the git resolver.

02

Real-world impact

A tenant able to create TaskRuns or PipelineRuns using the git resolver can exploit this to read any file on the resolver pod's filesystem. This includes ServiceAccount tokens, which could be used to access other cluster resources and escalate privileges.

03

Why this severity

CVSS 9.6 (critical) means the flaw is easy to exploit over a network, requires only low privileges, and can fully expose or alter data. The high score reflects that confidential and integrity controls are completely bypassed, though the system itself is not taken offline.

04

What to do about it

official fix available
recommended steps
  1. 01Identify which Tekton Pipelines version you are running.
  2. 02If you are on version 1.0.0, upgrade to 1.0.1 or later.
  3. 03If you are on a version in the 1.1–1.3.x range, upgrade to 1.3.3 or later.
  4. 04If you are on a version in the 1.4–1.6.0 range, upgrade to 1.6.1 or later.
  5. 05If you are on a version in the 1.7–1.9.1 range, upgrade to 1.9.2 or later.
  6. 06If you are on a version in the 1.10.0–1.10.1 range, upgrade to 1.10.2 or later.
  7. 07Apply the upgrade according to your Kubernetes deployment process and verify the new version is running.

NVD-referenced vendor advisory (patched versions listed in NVD description)

05

Timeline

  1. Mar 24, 2026 · Mar 24, 2026
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 20, 2026 · 16d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
  3. Aug 3, 2026 · 2d ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredLow
User interactionNone needed
ScopeChanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactNone
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →