What is CVE-2026-49478?
Fulcio is a certificate authority for issuing code signing certificates, and versions up to 1.8.5 improperly handle cross-host redirects during OIDC discovery, attaching Kubernetes ServiceAccount tokens. This allows a malicious or compromised issuer to steal these tokens. Users should immediately update to the patched version.
Azərbaycanca: Fulcio kod imzalama sertifikatları verən bir sertifikat orqanıdır və 1.8.5-ə qədər versiyalarda OIDC kəşfi zamanı çarpaz host yönləndirmələrini düzgün idarə etmir. Bu zəiflik təhlükəli və ya kompromatlaşmış bir issuer-a Kubernetes ServiceAccount token-lərini oğurlamaq imkanı verir. İstifadəçilər dərhal müvafiq versiyaya yeniləməlidir.
FAQ2
Which versions of Fulcio are affected by CVE-2026-49478?
Versions up to 1.8.5 are affected by this vulnerability.
What can a successful attacker steal by exploiting CVE-2026-49478?
A malicious or compromised issuer can steal Kubernetes ServiceAccount tokens.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.