🛡️ CVE Monitor
Dịch vụ / phần mềm liên quan: Chưa phân loại — không khớp danh sách dịch vụ/phần mềm đang theo dõi (xem/thêm ở internal/cve/categories.go), hoặc NVD chưa cung cấp đủ dữ liệu vendor/sản phẩm cho CVE này.

Mô tả

kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. Attackers can exploit this by using percent-encoded directory traversal sequences to create MutatingWebhookConfiguration objects cluster-wide or PolicyException objects in the kyverno namespace, enabling privilege escalation to cluster admin.

Chi tiết

Trạng tháiAwaiting Analysis
Điểm CVSS9.9 (v3.1)
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Ngày công bố21:16 26/09/2026
Ngày cập nhật22:20 28/09/2026
Nguồn dữ liệunvd

CWE

  • CWE-441

Sản phẩm bị ảnh hưởng

Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.

Tài liệu tham khảo

Lịch sử thay đổi

Thời gianLoạiTrườngGiá trị cũGiá trị mới
22:27 28/09/2026 CREATED cve CRITICAL

Tất cả thời gian trên trang này hiển thị theo giờ Việt Nam (GMT+7).