PT-2026-66597 · Capsule · Capsule

CVE-2026-65835

·

Published

2026-07-30

·

Updated

2026-09-04

CVSS v3.1

6.6

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Capsule versions 0.13.0 through 0.13.7
Description TenantResource RawItems and Generators in internal/controllers/resources/collect.go, specifically within the handleRawItem() and handleGeneratorItem() functions, fail to apply the ResourceReference.LoadResources and IsNamespacedGVK cluster-scoped resource rejection guards. This allows a Tenant Owner to create cluster-scoped resources, such as ClusterRole or ValidatingWebhookConfiguration, by leveraging the cluster-admin controller client.
Recommendations Update to version 0.13.8.

Exploit

Fix

Improper Privilege Management

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65835
GHSA-JR6P-8PJJ-MFX6
GO-2026-6157
OPENSUSE-SU-2026:21761-1

Affected Products

Capsule