CVE-2026-33381Disclosed before NVD

Users can generate Service Account tokens after permissions removal

Published
May 13, 2026
Last Modified

📋 Description

When a user’s access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this. This vulnerability was reported via our bug bounty program.

🔗 References (1)