CVE-2026-54167 | TektonCD Pipelines-as-Code up to 0.37.7/0.39.5/0.42.0/0.47.x GitHub App Provider improper authentication

SecurityVulns

A vulnerability identified as critical has been detected in TektonCD Pipelines-as-Code up to 0.37.7/0.39.5/0.42.0/0.47.x. The affected element is an unknown function of the component GitHub App Provider. This manipulation causes improper authentication.

This vulnerability is registered as CVE-2026-54167. Remote exploitation of the attack is possible. No exploit is available.

You should upgrade the affected component.VulDB Recent EntriesRead More