在 Kyverno 1.19.1 版本之前,namespaced Policy(命名空间作用域策略)资源中的 apiCall 上下文入口存在命名空间隔离绕过漏洞。该漏洞源于验证阶段与执行阶段对路径解释的不一致。低权限租户可以利用 urlPath 中的百分号编码的点段(dot-segments)来绕过命名空间检查,并通过 Kyverno 准入控制器的 ServiceAccount 凭证,读取其他命名空间中的资源。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100706 | 9.9 CRITICAL | kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath |
| CVE-2026-100704 | 7.7 HIGH | Kyverno before 1.19.1 ImageValidatingPolicy Exception Bypass |
| CVE-2026-100703 | 7.7 HIGH | Kyverno before 1.19.1 Cross-Namespace Data Access via globalcontext.Lib |
| CVE-2026-100705 | 7.6 HIGH | Kyverno before 1.19.1 SSRF via legacy apiCall service executor |
No comments yet