CVE-2026-54168 | Tekton Pipelines-as-Code up to 0.37.7/0.39.5/0.42.0/0.47.x Token Scoping ScopeTokenToListOfRepos privileges management
A vulnerability was found in Tekton Pipelines-as-Code up to 0.37.7/0.39.5/0.42.0/0.47.x and classified as problematic. Affected by this issue is the function ScopeTokenToListOfRepos of the component Token Scoping. Such manipulation leads to improper privilege management.
This vulnerability is referenced as CVE-2026-54168. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More