PT-2026-84160 · Kyverno · Kyverno
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kyverno versions prior to 1.16.2
Description
A server-side request forgery (SSRF) issue exists in the APICall feature. The
URL field within a Policy's ServiceCall configuration lacks validation, allowing a user with namespace-level Policy creation permissions to force the system to make HTTP requests to arbitrary internal resources, such as cloud metadata endpoints or resources belonging to other tenants. This is a Confused Deputy problem, where the system uses its high-privilege cluster-wide ServiceAccount to execute requests. Consequently, sensitive data, including cloud IAM credentials and secrets from other tenants, may be returned in the PolicyReport and accessed by the attacker, compromising multi-tenant isolation.Recommendations
Update to version 1.16.2 or later.
As a temporary mitigation, restrict the use of the
URL field in ServiceCall configurations or limit Policy creation permissions for users in multi-tenant environments.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kyverno