When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 13 May 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 |
Wed, 13 May 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this. | |
| Title | Users can generate Service Account tokens after permissions removal | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GRAFANA
Published:
Updated: 2026-05-13T19:35:08.982Z
Reserved: 2026-03-19T07:55:06.978Z
Link: CVE-2026-33381
No data.
Status : Received
Published: 2026-05-13T20:16:20.803
Modified: 2026-05-13T20:16:20.803
Link: CVE-2026-33381
No data.
OpenCVE Enrichment
Updated: 2026-05-13T22:15:09Z
Weaknesses