PT-2026-99378 · Kyverno · Kyverno

·

CVE-2026-100707

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kyverno versions prior to 1.19.1
Description An issue exists in the apiCall context entry of namespaced Policy resources caused by inconsistent path interpretation between validation and execution. A low-privilege tenant can utilize percent-encoded dot-segments in the urlPath variable to bypass namespace isolation checks. This allows the attacker to read resources from other namespaces by leveraging the Kyverno admission controller's ServiceAccount credentials.
Recommendations Update to version 1.19.1 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100707
GHSA-C5QQ-7G2Q-CPQP

Affected Products

Kyverno