<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Kyverno (1.16.0 - 1.19.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/kyverno-1.16.0---1.19.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 26 Sep 2026 14:59:10 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/kyverno-1.16.0---1.19.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-100706: Path Traversal in Kyverno Policy apiCall Processing</title><link>https://feed.craftedsignal.io/briefs/2026-09-kyverno-path-traversal/</link><pubDate>Sat, 26 Sep 2026 14:59:10 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-kyverno-path-traversal/</guid><description>Kyverno versions before 1.19.1 contain a path traversal vulnerability in apiCall urlPath processing, enabling namespace-restricted users to perform unauthorized cluster-wide object manipulation via URL-encoded segments.</description><content:encoded><![CDATA[<p>Kyverno versions prior to 1.19.1 are susceptible to a critical path traversal vulnerability within the Policy apiCall component. The vulnerability resides in the insufficient validation of URL-encoded path segments within the 'urlPath' field. This flaw allows a namespace-restricted tenant to bypass enforced namespace boundaries by using percent-encoded directory traversal sequences. When exploited, the attacker effectively elevates their privileges to that of the Kyverno admission-controller ServiceAccount. This level of access allows the attacker to create or modify sensitive cluster-wide resources, including MutatingWebhookConfiguration objects or PolicyException objects within the 'kyverno' namespace, ultimately resulting in full cluster-admin escalation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a restricted tenant to break out of their assigned namespace context. This can lead to total cluster compromise through the injection of malicious webhook configurations, which intercept and modify arbitrary Kubernetes API requests, or by creating policy exceptions that disable security controls across the entire cluster.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade all Kyverno deployments to version 1.19.1 or later immediately.</li>
<li>Audit current Policy resources for any 'apiCall' configurations utilizing 'urlPath' parameters until patches are applied.</li>
<li>Restrict permissions for creating or modifying Kyverno Policy resources to trusted cluster administrators to mitigate the potential impact of the vulnerability while pending upgrades.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>kyverno</category><category>path-traversal</category><category>kubernetes</category><category>privilege-escalation</category><category>vulnerability</category><category>cloud-native</category></item></channel></rss>