PT-2026-99377 · Kyverno · Kyverno
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
kyverno versions prior to 1.19.1
Description
Insufficient validation of URL-encoded path segments in the Policy
apiCall urlPath allows namespace tenants to bypass the per-namespace clamp. This enables the creation of objects in other namespaces using the admission-controller ServiceAccount. By utilizing percent-encoded directory traversal sequences, an attacker can create MutatingWebhookConfiguration objects cluster-wide or PolicyException objects within the kyverno namespace, leading to privilege escalation to cluster admin.Recommendations
Update kyverno to version 1.19.1 or later.
Exploit
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kyverno