Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-100706: Kyverno lets users create objects in other namespaces
CVE-2026-100706 · published 1 day ago
Summary
Kyverno versions earlier than 1.19.1 do not correctly check specially encoded URLs in its policy calls. This mistake lets a user in one namespace create resources, such as webhooks or policy exceptions, in other namespaces or even cluster‑wide, effectively gaining higher privileges. Upgrade Kyverno to version 1.19.1 or later, or apply the vendor’s patch, to close the gap.
What to do
- Update kyverno kyverno to version 1.19.1 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| kyverno | kyverno | < 1.19.1 |
Original advisory text
kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath
kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. Attackers can exploit this by using percent-encoded directory traversal sequences to create MutatingWebhookConfiguration objects cluster-wide or PolicyException objects in the kyverno namespace, enabling privilege escalation to cluster admin.
References
- https://github.com/kyverno/kyverno/security/advisories/GHSA-5qq8-67g6-4h2w Vendor Advisory
- https://www.vulncheck.com/advisories/kyverno-before-1.19.1-privilege-escalation-... Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-1007... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-100706 Vendor Advisory
Severity
9.4
Critical
CVSS 3.1: 9.9 (MITRE)
Type
CWE-441Unintended Proxy or Intermediary ('Confused Deputy')
Timeline
Published26 Sep 2026
Updated27 Sep 2026
First seen26 Sep 2026
Sources
CVE-2026-100706 · NVD
CVE-2026-100706 · MITRE
CVE-2026-100706 · OSV
GHSA-5qq8-67g6-4h2w · GHSA
Track software like this
Free during beta