Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100707— Kyverno before 1.19.1 Namespace Isolation Bypass via Percent-Encoded Path

Quick assessment

Affected
kyverno kyverno
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Kyverno 1.19.1 版本之前,namespaced Policy(命名空间作用域策略)资源中的 apiCall 上下文入口存在命名空间隔离绕过漏洞。该漏洞源于验证阶段与执行阶段对路径解释的不一致。低权限租户可以利用 urlPath 中的百分号编码的点段(dot-segments)来绕过命名空间检查,并通过 Kyverno 准入控制器的 ServiceAccount 凭证,读取其他命名空间中的资源。

CVSS 7.7 · High EPSS 0.46% · P37
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100707

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kyverno before 1.19.1 Namespace Isolation Bypass via Percent-Encoded Path
Source: CVE Program / CVE List V5
Vulnerability Description
Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of namespaced Policy resources due to inconsistent path interpretation between validation and execution. A low-privilege tenant can use percent-encoded dot-segments in urlPath to bypass namespace checks and read resources from other namespaces using the Kyverno admission controller's ServiceAccount credentials.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
kyverno kyverno 0 ~ 1.19.1 -

II. Public POCs for CVE-2026-100707

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100707

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100707 (1)

Other References for CVE-2026-100707 (1)

Same Patch Batch · kyverno · 2026-09-26 · 5 CVEs total

CVE-2026-100706 9.9 CRITICAL kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath
CVE-2026-100704 7.7 HIGH Kyverno before 1.19.1 ImageValidatingPolicy Exception Bypass
CVE-2026-100703 7.7 HIGH Kyverno before 1.19.1 Cross-Namespace Data Access via globalcontext.Lib
CVE-2026-100705 7.6 HIGH Kyverno before 1.19.1 SSRF via legacy apiCall service executor

IV. Related Vulnerabilities

V. Comments for CVE-2026-100707

No comments yet


Leave a comment