PT-2026-95488 · Capsule · Capsule

CVE-2026-61672

·

Published

2026-09-18

·

Updated

2026-09-28

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Capsule versions prior to 0.13.7
Description An issue exists in the ForbiddenListSpec.ExactMatch() function within pkg/api/forbidden list.go where denied metadata keys are sorted case-insensitively but then searched using a byte-order binary search via sort.SearchStrings. When a forbidden list contains a mix of uppercase and lowercase keys, the binary search may fail to find a key that is actually present, returning a false negative.
An authenticated tenant owner can exploit this by passing a forbidden key through the api.ValidateForbidden() function to bypass restrictions on namespace, Service, or delegated node metadata. This could allow a tenant to influence cluster policies, increase network exposure, or affect scheduling outside their tenant boundary by setting forbidden labels or annotations (e.g., Pod Security Admission labels or cloud LoadBalancer annotations).
Recommendations Update Capsule to version 0.13.7. As a temporary workaround, ensure that all keys in the forbidden lists are uniformly lowercase to avoid the sorting discrepancy.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61672
GHSA-GJW4-3V3V-RQXG
GO-2026-6520

Affected Products

Capsule