PT-2026-84160 · Kyverno · Kyverno

·

CVE-2026-84199

·

Published

2026-04-14

·

Updated

2026-09-01

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kyverno versions prior to 1.16.2
Description A server-side request forgery (SSRF) issue exists in the APICall feature. The URL field within a Policy's ServiceCall configuration lacks validation, allowing a user with namespace-level Policy creation permissions to force the system to make HTTP requests to arbitrary internal resources, such as cloud metadata endpoints or resources belonging to other tenants. This is a Confused Deputy problem, where the system uses its high-privilege cluster-wide ServiceAccount to execute requests. Consequently, sensitive data, including cloud IAM credentials and secrets from other tenants, may be returned in the PolicyReport and accessed by the attacker, compromising multi-tenant isolation.
Recommendations Update to version 1.16.2 or later. As a temporary mitigation, restrict the use of the URL field in ServiceCall configurations or limit Policy creation permissions for users in multi-tenant environments.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84199
GHSA-FMQP-4WFC-W3V7
GO-2026-5371

Affected Products

Kyverno