CVE-2026-32604: Linuxfoundation Spinnaker

Critical severity, CVSS 9.9. EPSS: 0.8% chance of exploitation in the next 30 days.

Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands very simply on the clouddriver pods. This can expose credentials, remove files, or inject resources easily. Versions 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2 contain a patch. As a workaround, disable the gitrepo artifact types.

Affected products

  • Linuxfoundation Spinnaker: before 2025.3.2 (fixed in 2025.3.2); from 2025.4.0, before 2025.4.2 (fixed in 2025.4.2); from 2026.0.0, before 2026.0.1 (fixed in 2026.0.1)

Published 2026-04-20. Last modified 2026-06-17.