Bug 2460269 (CVE-2026-40923)

Summary: CVE-2026-40923 github.com/tektoncd/pipeline: Tekton Pipelines: Unauthorized access and information disclosure via path validation bypass
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aazores, abarbaro, abrianik, akostadi, akoudelk, alcohan, alebedev, alizardo, amasferr, amctagga, anjoseph, anpicker, ansmith, anthomas, aoconnor, asatyam, ataylor, bbrownin, bdettelb, bniver, bparees, chfoley, ckandaga, cmah, crizzo, csutherl, dbruscin, dfreiber, dhanak, diagrawa, dmayorov, doconnor, drosa, drow, dschmidt, dsimansk, dsoumis, dymurray, eaguilar, ebaron, eborisov, eglynn, ehelms, erezende, ewittman, fdeutsch, flucifre, ggainey, ggrzybek, gmeno, gparvin, groman, hasun, ibolton, jaharrin, janstey, jbalunas, jburrell, jcantril, jchui, jclere, jeder, jfula, jhe, jjoyce, jkoehler, jlanda, jlledo, jmatthew, jmontleo, jolong, jowilson, jprabhak, jpretori, jraez, jschluet, juwatts, kingland, kshier, ktsao, kvanderr, kverlaen, lball, lbragsta, lchilton, lgamliel, lhh, lphiri, manissin, mbenjamin, mbocek, mburns, mgarciac, mhackett, mhulan, mnovotny, mrunge, mwringe, nboldt, ngough, nipatil, nmoumoul, nyancey, oaljalju, ometelka, oramraz, osousa, pahickey, pantinor, parichar, pcreech, peholase, pgaikwad, pjindal, plodge, psrna, ptisnovs, pvasanth, rchan, rfreiman, rgodfrey, rhaigner, rjohnson, rkubis, rmaucher, rojacob, sabiswas, sakbas, sausingh, sdawley, sfeifer, simaishi, slucidi, smallamp, smcdonal, smullick, sostapov, sseago, stcannon, stirabos, swoodman, syedriko, szappis, tasato, teagle, thason, tmalecek, tsedmik, tzivkovi, vereddy, veshanka, vimartin, vkarehfa, vkumar, wenshen, whayutin, wtam, xdharmai, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Tekton Pipelines. An attacker can bypass restrictions on where volumes can be mounted by using specially crafted paths that include directory traversal sequences (e.g., `..`). This vulnerability, stemming from an incomplete path validation check, could allow unauthorized access to internal system directories, potentially leading to information disclosure or limited modification of sensitive data.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-04-21 21:01:20 UTC
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Prior to 1.11.1, a validation bypass in the VolumeMount path restriction allows mounting volumes under restricted /tekton/ internal paths by using .. path traversal components. The restriction check uses strings.HasPrefix without filepath.Clean, so a path like /tekton/home/../results passes validation but resolves to /tekton/results at runtime. This vulnerability is fixed in 1.11.1.