PT-2026-82334 · Kubepi · Kubepi

·

CVE-2026-69129

·

Published

2026-08-26

·

Updated

2026-08-27

CVSS v4.0

5.8

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions KubePi versions prior to 2.0.1
Description Cluster-scoped APIs do not consistently validate per-cluster access. This allows an authenticated user with cluster management permissions to operate on clusters outside their granted scope. Because the affected endpoints process cluster-specific data without confirming the requesting user's authorization for that specific cluster, a user with management rights over one cluster may read or modify data in other clusters under certain role and cluster configurations.
Recommendations Update to version 2.0.1.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-69129
GHSA-CWG7-34P9-9HXH

Affected Products

Kubepi