PT-2026-99377 · Kyverno · Kyverno

·

CVE-2026-100706

·

Published

2026-09-26

·

Updated

2026-09-27

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions kyverno versions prior to 1.19.1
Description Insufficient validation of URL-encoded path segments in the Policy apiCall urlPath allows namespace tenants to bypass the per-namespace clamp. This enables the creation of objects in other namespaces using the admission-controller ServiceAccount. By utilizing percent-encoded directory traversal sequences, an attacker can create MutatingWebhookConfiguration objects cluster-wide or PolicyException objects within the kyverno namespace, leading to privilege escalation to cluster admin.
Recommendations Update kyverno to version 1.19.1 or later.

Exploit

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100706
GHSA-5QQ8-67G6-4H2W

Affected Products

Kyverno