在 Kyverno 1.19.1 之前的版本中,Policy 的 apiCall urlPath 未能正确验证 URL 编码的路径段,允许命名空间租户绕过每个命名空间的限制,并以 admission-controller ServiceAccount 的身份在其他命名空间中创建对象。攻击者可以通过使用百分号编码的路径遍历序列来利用此漏洞,从而在全集群范围内创建 MutatingWebhookConfiguration 对象或在 kyverno 命名空间中创建 PolicyException 对象,进而实现权限提升至
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100704 | 7.7 HIGH | Kyverno before 1.19.1 ImageValidatingPolicy Exception Bypass |
| CVE-2026-100707 | 7.7 HIGH | Kyverno before 1.19.1 Namespace Isolation Bypass via Percent-Encoded Path |
| CVE-2026-100703 | 7.7 HIGH | Kyverno before 1.19.1 Cross-Namespace Data Access via globalcontext.Lib |
| CVE-2026-100705 | 7.6 HIGH | Kyverno before 1.19.1 SSRF via legacy apiCall service executor |
No comments yet