PT-2026-99374 · Kyverno · Kyverno

·

CVE-2026-100703

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kyverno versions 1.16.0 through 1.19.0
Description The software registers the globalcontext.Lib Common Expression Language (CEL) library in its policy environment without restricting it to the policy's namespace. This differs from other libraries like resource.Lib, http.Lib, and the configMap loader, which are confined to the policy namespace. A tenant with permissions to create namespaced policies, such as NamespacedValidatingPolicy or similar mutating, deleting, generating, and image-validating policies, can use the globalContext.get() function to retrieve the full cached contents of a cluster-scoped GlobalContextEntry. This allows access to data cached from namespaces for which the tenant lacks RBAC (Role-Based Access Control) permissions, as no admission validation prevents these calls.
Recommendations Update Kyverno to version 1.19.1.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100703
GHSA-59V6-2X73-WFG4

Affected Products

Kyverno