Spinnaker patched two high-severity remote code execution vulnerabilities that could let attackers run arbitrary commands in core services of the multi-cloud continuous delivery platform. CVE-2026-32604 affects deployments using gitrepo artifact types, where improper sanitization of user-controlled branch names and paths can lead to command execution on clouddriver pods, potentially exposing credentials, deleting files, or injecting resources into the environment.
A second flaw, CVE-2026-32613, impacts the Echo service through unsafe Spring Expression Language handling for expected artifacts, allowing unrestricted access to Java classes and enabling command execution, file access, and broader system compromise. The issues were fixed in Spinnaker versions 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2; organizations that cannot patch immediately can reduce risk by disabling gitrepo artifact types and, for the Echo issue, disabling Echo entirely.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Spinnaker patched CVE-2026-32613 in versions 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2 after unsafe Spring Expression Language handling in the Echo service exposed unrestricted JVM access. For unpatched deployments, administrators were advised to disable Echo entirely.
Spinnaker released versions 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2 to patch CVE-2026-32604, a vulnerability that allowed arbitrary command execution on clouddriver pods via improper sanitization of gitrepo artifact branch and path input. As a temporary mitigation, users were advised to disable gitrepo artifact types.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
ccb.belgium.be
Open sourcereddit.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcebugflation.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.