Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-69129— KubePi: Insufficient per-cluster authorization checks in cluster management APIs

Quick assessment

Affected
1Panel-dev KubePi
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

KubePi 是一个用于管理多个 Kubernetes 集群的面板软件。在 2.0.0 及之前版本中,集群作用域的 API 未对每个集群的访问权限进行一致性的校验,使得拥有集群管理权限的已认证用户能够操作其未被授权的集群。由于受影响的端点会直接操作特定集群的数据,而未验证请求用户是否对该特定集群具有相应权限,因此在某些角色和集群配置下,仅被赋予某个集群管理权限的用户,可能读取或修改本不应由其管理的其他集群中的数据。该问题已在 2.0.1 版本中修复。

CVSS 5.8 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-69129

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
KubePi: Insufficient per-cluster authorization checks in cluster management APIs
Source: CVE Program / CVE List V5
Vulnerability Description
KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 2.0.0, cluster-scoped APIs do not consistently validate per-cluster access, allowing an authenticated user with cluster management permissions to operate on clusters outside the scope they were granted. Because the affected endpoints act on cluster-specific data without confirming that the requesting user is authorized for that particular cluster, a user assigned management rights over one cluster can, under certain role and cluster configurations, read or modify data in clusters they should not manage. This issue is fixed in version 2.0.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
1Panel-dev KubePi < 2.0.1 -

II. Public POCs for CVE-2026-69129

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-69129

登录查看更多情报信息。

Patches & Fixes for CVE-2026-69129 (1)

Vendor Advisories for CVE-2026-69129 (1)

Vendor Pages for CVE-2026-69129 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-69129

No comments yet


Leave a comment