Threat Advisory

Fission Flaw Allows Tenant-Added CAP_SYS_TIME and Cross-Tenant Node Wall-Clock Corruption

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high severity vulnerability, CVE-2026-50570 with a CVSS score of 8.5, exists in Fission due to an incomplete capability denylist in Environment/Function PodSpec validation. This flaw allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption via incomplete capability denylist in Environment/Function PodSpec validation, specifically omitting CAP_SYS_TIME among others. As a result, an attacker-controlled code execution with CAP_SYS_TIME in the resulting function or runtime container can corrupt TLS / certificate validity windows, Kubernetes lease renewal, token expiry, scheduling, and time-series for every workload on the node. The vulnerability affects Fission versions less than or equal to 1.24.0. A capability allowlist is necessary to address both problems of incomplete denylists and capabilities granted by default by the OCI runtime. This flaw can be exploited through a tenant who could create a Function or Environment CRD, request securityContext.capabilities.add: ["SYS_TIME"], pass Fission's admission validation and merge-layer sanitization, and run attacker-controlled code with CAP_SYS_TIME in the resulting function or runtime container.

RECOMMENDATION:

We recommend you to update Fission to version 1.25.0.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high severity vulnerability, CVE-2026-50570 with a CVSS score of 8.5, exists in Fission due to an incomplete capability denylist in Environment/Function PodSpec validation. This flaw allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption via incomplete capability denylist in Environment/Function PodSpec validation, specifically omitting CAP_SYS_TIME among others. As a result, an attacker-controlled code execution with CAP_SYS_TIME in the resulting function or runtime container can corrupt TLS / certificate validity windows, Kubernetes lease renewal, token expiry, scheduling, and time-series for every workload on the node. The vulnerability affects Fission versions less than or equal to 1.24.0. A capability allowlist is necessary to address both problems of incomplete denylists and capabilities granted by default by the OCI runtime. This flaw can be exploited through a tenant who could create a Function or Environment CRD, request securityContext.capabilities.add: ["SYS_TIME"], pass Fission's admission validation and merge-layer sanitization, and run attacker-controlled code with CAP_SYS_TIME in the resulting function or runtime container.

RECOMMENDATION:

We recommend you to update Fission to version 1.25.0.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu