Kubepi · Kubepi · CVE-2026-69129
**Name of the Vulnerable Software and Affected Versions**
KubePi versions prior to 2.0.1
**Description**
Cluster-scoped APIs do not consistently validate per-cluster access. This allows an authenticated user with cluster management permissions to operate on clusters outside their granted scope. Because the affected endpoints process cluster-specific data without confirming the requesting user's authorization for that specific cluster, a user with management rights over one cluster may read or modify data in other clusters under certain role and cluster configurations.
**Recommendations**
Update to version 2.0.1.