PT-2026-91928 · Unknown · Kubesphere

·

CVE-2026-91923

·

Published

2026-09-15

·

Updated

2026-09-18

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions KubeSphere versions prior to 4.1.4
Description An issue exists in the git credential verification endpoint that accepts unvalidated caller-supplied URLs without allowlist restrictions. Authenticated attackers can provide arbitrary URLs to access internal services and exfiltrate basic-auth credentials from Secrets in any namespace by exploiting the error response handling of the endpoint. Server-side request forgery (SSRF) is a flaw where an attacker induces a server-side application to make requests to an unintended location.
Recommendations Update to version 4.1.4 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91923

Affected Products

Kubesphere