PT-2026-84158 · Kyverno · Kyverno

·

CVE-2026-84195

·

Published

2026-04-16

·

Updated

2026-09-01

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kyverno versions prior to 1.16.4
Description In apiCall service mode, the admission controller automatically attaches its ServiceAccount token to outbound HTTP requests when explicit authorization headers are absent. This allows an attacker to exfiltrate the token by directing apiCall requests to external or attacker-controlled endpoints, potentially granting full control over cluster resources and Kyverno policies.
Recommendations Update to version 1.16.4 or later.

Exploit

Fix

Insufficiently Protected Credentials

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84195
GHSA-8WFP-579W-6R25
GO-2026-5268

Affected Products

Kyverno