{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3akyvernokyverno/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:kyverno:kyverno:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-100706"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["kyverno (\u003c 1.19.1)","Kyverno (1.16.0 - 1.19.0)","Kyverno (1.14.0 - 1.19.0)"],"_cs_severities":["critical"],"_cs_tags":["kyverno","path-traversal","kubernetes","privilege-escalation","vulnerability","cloud-native"],"_cs_type":"advisory","_cs_vendors":["Kyverno"],"content_html":"\u003cp\u003eKyverno versions prior to 1.19.1 are susceptible to a critical path traversal vulnerability within the Policy apiCall component. The vulnerability resides in the insufficient validation of URL-encoded path segments within the 'urlPath' field. This flaw allows a namespace-restricted tenant to bypass enforced namespace boundaries by using percent-encoded directory traversal sequences. When exploited, the attacker effectively elevates their privileges to that of the Kyverno admission-controller ServiceAccount. This level of access allows the attacker to create or modify sensitive cluster-wide resources, including MutatingWebhookConfiguration objects or PolicyException objects within the 'kyverno' namespace, ultimately resulting in full cluster-admin escalation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a restricted tenant to break out of their assigned namespace context. This can lead to total cluster compromise through the injection of malicious webhook configurations, which intercept and modify arbitrary Kubernetes API requests, or by creating policy exceptions that disable security controls across the entire cluster.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all Kyverno deployments to version 1.19.1 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit current Policy resources for any 'apiCall' configurations utilizing 'urlPath' parameters until patches are applied.\u003c/li\u003e\n\u003cli\u003eRestrict permissions for creating or modifying Kyverno Policy resources to trusted cluster administrators to mitigate the potential impact of the vulnerability while pending upgrades.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-26T15:13:31Z","date_published":"2026-09-26T14:59:10Z","id":"https://feed.craftedsignal.io/briefs/2026-09-kyverno-path-traversal/","summary":"Kyverno versions before 1.19.1 contain a path traversal vulnerability in apiCall urlPath processing, enabling namespace-restricted users to perform unauthorized cluster-wide object manipulation via URL-encoded segments.","title":"CVE-2026-100706: Path Traversal in Kyverno Policy apiCall Processing","url":"https://feed.craftedsignal.io/briefs/2026-09-kyverno-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:kyverno:kyverno:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}