PT-2026-95488 · Capsule · Capsule
CVE-2026-61672
·
Published
2026-09-18
·
Updated
2026-09-28
CVSS v3.1
7.1
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Capsule versions prior to 0.13.7
Description
An issue exists in the
ForbiddenListSpec.ExactMatch() function within pkg/api/forbidden list.go where denied metadata keys are sorted case-insensitively but then searched using a byte-order binary search via sort.SearchStrings. When a forbidden list contains a mix of uppercase and lowercase keys, the binary search may fail to find a key that is actually present, returning a false negative.An authenticated tenant owner can exploit this by passing a forbidden key through the
api.ValidateForbidden() function to bypass restrictions on namespace, Service, or delegated node metadata. This could allow a tenant to influence cluster policies, increase network exposure, or affect scheduling outside their tenant boundary by setting forbidden labels or annotations (e.g., Pod Security Admission labels or cloud LoadBalancer annotations).Recommendations
Update Capsule to version 0.13.7.
As a temporary workaround, ensure that all keys in the forbidden lists are uniformly lowercase to avoid the sorting discrepancy.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Capsule