All vulnerabilities
CRITICALAI/LLMexploited in the wildcurated

AI-SAPWNED-2024

SAP AI Core · SAP AI Core

Summary

SAPwned, disclosed by Wiz in 2024, is what cloud cross-tenant attacks look like in the AI era. SAP AI Core runs customers' machine-learning training jobs, and a training job is, fundamentally, someone else's code running on shared infrastructure. Researchers submitted a perfectly legitimate-looking training job and used it to escape the boundaries that were supposed to keep tenants apart, chaining several weaknesses until they had cluster-admin and could reach other customers' secrets, cloud credentials, and private AI models. It is the lesson that AI platforms inherit every hard cloud-isolation problem and add a new one: they are designed to run untrusted code.

How it happened

Wiz Research chained several weaknesses to break tenant isolation on SAP AI Core. They started by submitting a legitimate-looking training job (technically an Argo Workflow), which is exactly what the service is built to run. They configured the pod to read the Istio sidecar's token and bypass the network segmentation that was meant to fence tenants off from each other. That let them reach unauthenticated internal services: a Grafana Loki logging instance that was leaking AWS credentials, six unauthenticated AWS EFS file shares holding other customers' code and training data keyed by customer ID, and an exposed Helm 2 Tiller server.

The Helm server was the final lever. Using its write access, they deployed a malicious package that granted them cluster-admin, and with cluster-admin they had cross-tenant access to other customers' pods, secrets, and cloud credentials for AWS, Azure, and SAP HANA, plus a write-capable container-registry key that could have let them poison SAP's own Docker images and spread the attack further. SAP fixed all of the issues by May 2024 (after Wiz bypassed an initial patch with two more flaws) and stated that no customer data was compromised; the chain was found by researchers, not exploited in the wild.

The damage

SAPwned was a proof of concept rather than a real-world breach, but the potential was severe: any SAP AI Core customer could in principle have reached every other customer's training data, models, and cloud keys. Its real significance was in spotlighting AI and ML platforms as a fresh and rich cross-tenant attack surface, one that will only grow as more companies run their models on shared managed infrastructure.

Why SAPwned still matters

AI training platforms are uniquely exposed, because their entire job is to run customer-supplied code, the training job. That means the isolation between tenants has to be airtight, and here it was not: a training job became cluster-admin. It is essentially ChaosDB for the AI era, the same truth that cloud multi-tenancy is software that can fail, with the added twist that AI infrastructure runs untrusted code by design. The defences: enforce strong tenant isolation and network segmentation so a tenant pod cannot reach internal services, lock down service tokens, internal logging, shares, and Helm behind authentication and least privilege, treat training-job inputs as untrusted and sandbox the workloads, restrict cluster RBAC, and rotate any exposed credentials. As AI platforms proliferate, this class of flaw will keep recurring.

How to fix it

  • Apply the provider's fixes and rotate any cloud credentials the isolation break could have exposed.
  • Lock down internal services (logging, shares, Helm) behind authentication and least privilege so a tenant pod cannot reach them.
  • Audit cross-tenant access paths and restrict cluster RBAC so a training job cannot escalate to cluster-admin.

How to avoid it

  • Apply SAP's fixes (patched by May 2024) and keep AI Core platform components updated.
  • Enforce strong tenant isolation and network segmentation; block pods from reaching internal services.
  • Lock down service tokens, internal logging, shares, and Helm with authentication and least privilege.
  • Treat training-job inputs as untrusted; sandbox workloads and restrict cluster RBAC.
  • Rotate exposed cloud credentials and audit cross-tenant access paths.

References

Related vulnerabilities

All AI/LLM →