{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/maas-api/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-14450"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MaaS API"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["MaaS"],"content_html":"\u003cp\u003eA critical authentication vulnerability (CVE-2026-14450) exists in the MaaS API, where the service implicitly trusts specific HTTP headers for identity verification. By forging the 'X-MaaS-Username' and 'X-MaaS-Group' headers, any pod deployed within the same Kubernetes cluster can circumvent the Kuadrant AuthPolicy gateway. This bypass renders the platform's multi-tenancy controls ineffective, as the API accepts the provided claims without secondary validation or cryptographic proof. An attacker within the cluster environment can impersonate administrative users or other tenants, leading to unauthorized API interactions. This is particularly dangerous in multi-tenant environments where shared infrastructure relies on these specific headers to partition resources and enforce authorization.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full tenant impersonation within the cluster. Concrete impact includes the unauthorized minting of Kubernetes ServiceAccount tokens in foreign namespaces, the ability to revoke legitimate API keys, and the exfiltration of sensitive model access configurations and tenant secrets. Given the CVSS score of 9.9, this vulnerability permits complete control over the affected MaaS API instances.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately review ingress and gateway configurations to ensure that 'X-MaaS-Username' and 'X-MaaS-Group' headers are stripped or validated at the network perimeter before reaching the MaaS API backend.\u003c/li\u003e\n\u003cli\u003eImplement strict mTLS and network policies to isolate pods and limit their ability to communicate directly with the MaaS API unless explicitly authorized.\u003c/li\u003e\n\u003cli\u003eMonitor service mesh or API gateway logs for unexpected HTTP requests containing non-standard or administrative values in the 'X-MaaS' header set.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-10T21:35:50Z","date_published":"2026-08-10T21:35:50Z","id":"https://feed.craftedsignal.io/briefs/2026-08-maas-api-bypass/","summary":"The MaaS API incorrectly trusts X-MaaS-Username and X-MaaS-Group headers, allowing internal cluster pods to bypass authentication and escalate privileges to other tenants.","title":"Authentication Bypass in MaaS API via Header Forgery","url":"https://feed.craftedsignal.io/briefs/2026-08-maas-api-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - MaaS API","version":"https://jsonfeed.org/version/1.1"}