Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-84200— Kyverno before v1.13.0 Policy Bypass via Multiple Exceptions

Quick assessment

Affected
kyverno kyverno
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Kyverno v1.9.0 至 v1.12.7 版本中存在策略异常处理缺陷。当一个处于强制执行(enforce)模式的策略与两个 PolicyException(策略异常)结合使用时,限制较宽松的那个异常会优先生效。攻击者可以构造匹配第二个异常名称模式(例如 'ingress')的资源名称,从而绕过该策略。此缺陷可被用于规避诸如禁止使用 hostPath 卷之类的策略。该问题已在 v1.13.0 中修复。

CVSS 9.0 · Critical

Possible ATT&CK Techniques 1 AI

T1210 · Exploitation of Remote Services
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-84200

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kyverno before v1.13.0 Policy Bypass via Multiple Exceptions
Source: CVE Program / CVE List V5
Vulnerability Description
Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive exception takes precedence, allowing an attacker to bypass the policy by crafting a resource name that matches the second exception's name pattern (e.g., '*ingress*'). This can be used to circumvent policies such as one blocking hostPath volumes. Fixed in v1.13.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
访问控制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
kyverno kyverno 0 ~ 1.13.0 -

II. Public POCs for CVE-2026-84200

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-84200

登录查看更多情报信息。

Other References for CVE-2026-84200 (2)

Same Patch Batch · kyverno · 2026-09-01 · 6 CVEs total

CVE-2026-84199 7.7 HIGH Kyverno before 1.16.2 SSRF via APICall Feature
CVE-2026-84195 7.7 HIGH Kyverno before 1.16.4 Credential Leak via apiCall
CVE-2026-84196 7.7 HIGH Kyverno before 1.18.0 Server-Side Request Forgery via apiCall
CVE-2025-15613 6.5 MEDIUM Kyverno before v1.13.4 SSRF via Service Call
CVE-2023-54356 3.7 LOW Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites

IV. Related Vulnerabilities

V. Comments for CVE-2026-84200

No comments yet


Leave a comment