← CVEs and Advisories

CVE-2026-63013

NationalSecurityAgency/skills-service · Severity High (CVSS 8.8) · Discovered by Pavan Nallamothu

A low-privilege user could assign themselves to an administrative group, escalating to full administrative control of the NSA skills-service application.

Summary

Privilege escalation via unauthorized admin-group assignment.

References

cve.org record · GitHub Security Advisory GHSA-67x3-r85f-822r