Kyverno · Kyverno · CVE-2026-100703
**Name of the Vulnerable Software and Affected Versions**
Kyverno versions 1.16.0 through 1.19.0
**Description**
The software registers the `globalcontext.Lib` Common Expression Language (CEL) library in its policy environment without restricting it to the policy's namespace. This differs from other libraries like `resource.Lib`, `http.Lib`, and the configMap loader, which are confined to the policy namespace. A tenant with permissions to create namespaced policies, such as `NamespacedValidatingPolicy` or similar mutating, deleting, generating, and image-validating policies, can use the `globalContext.get()` function to retrieve the full cached contents of a cluster-scoped `GlobalContextEntry`. This allows access to data cached from namespaces for which the tenant lacks RBAC (Role-Based Access Control) permissions, as no admission validation prevents these calls.
**Recommendations**
Update Kyverno to version 1.19.1.