{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/kcp-dev/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:kcp-dev:kcp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-61682"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["kcp (\u003c 0.31.4, \u003e= 0.32.0, \u003c 0.32.2)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["kcp-dev"],"content_html":"\u003cp\u003eThe kcp-dev kcp platform contains a critical vulnerability (CVE-2026-61682) where the front-proxy fails to remove client-supplied \u003ccode\u003eX-Remote-*\u003c/code\u003e identity headers before forwarding requests to backend shards. In a kcp sharded architecture, the front-proxy authenticates users and communicates their identity to shards via these headers. Because the front-proxy performs an insecure append operation rather than a replace/sanitize operation, an authenticated attacker can inject their own forged headers into the request.\u003c/p\u003e\n\u003cp\u003eBy crafting requests with custom \u003ccode\u003eX-Remote-Group\u003c/code\u003e or \u003ccode\u003eX-Remote-Extra-*\u003c/code\u003e headers, an attacker can assert elevated privileges, specifically \u003ccode\u003esystem:masters\u003c/code\u003e, or forge warrants and scopes to break workspace isolation. This allows any authenticated user to gain cluster-administrator access, enabling read, write, and delete operations across all tenants and workspaces managed by the affected shard. The vulnerability was identified and disclosed in September 2026 and affects specific versions of the kcp binary.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains valid low-privilege authentication credentials (e.g., client certificate, OIDC token, or service account token) valid for the kcp environment.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP request targeting a resource managed by a kcp shard.\u003c/li\u003e\n\u003cli\u003eAttacker injects malicious \u003ccode\u003eX-Remote-Group: system:masters\u003c/code\u003e and \u003ccode\u003eX-Remote-Extra-*\u003c/code\u003e headers into the request.\u003c/li\u003e\n\u003cli\u003eAttacker sends the crafted request to the kcp front-proxy.\u003c/li\u003e\n\u003cli\u003eFront-proxy authenticates the attacker but fails to strip the pre-existing, malicious identity headers.\u003c/li\u003e\n\u003cli\u003eFront-proxy forwards the request along with the original injected headers to the target shard.\u003c/li\u003e\n\u003cli\u003eThe shard processes the identity headers as trusted assertions from the front-proxy.\u003c/li\u003e\n\u003cli\u003eAttacker gains unauthorized administrative access to the targeted workspace or the entire shard, allowing data exfiltration or destructive actions.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a total breakdown of multi-tenant security boundaries within a kcp cluster. An attacker can access, modify, or delete any resource, including secrets, APIExports, and LogicalClusters, across all workspaces on the compromised shard. The potential impact is widespread data breach and full cluster takeover, affecting any organization utilizing sharded kcp deployments for multi-tenant service hosting.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate upgrade of all kcp front-proxy and shard components to version 0.31.4 or 0.32.2. No configuration changes are required following the patch. In environments where immediate patching is not feasible, implement a strict front-end proxy layer (e.g., Nginx, Envoy, or HAProxy) positioned before the kcp front-proxy that explicitly strips all \u003ccode\u003eX-Remote-\u003c/code\u003e prefixed headers from inbound client requests. Monitor webserver logs for requests containing headers such as \u003ccode\u003eX-Remote-Group\u003c/code\u003e or \u003ccode\u003eX-Remote-Extra\u003c/code\u003e originating from client IP addresses to identify potential exploitation attempts.\u003c/p\u003e\n","date_modified":"2026-09-18T19:48:14Z","date_published":"2026-09-18T19:48:14Z","id":"https://feed.craftedsignal.io/briefs/2026-09-kcp-auth-bypass/","summary":"The kcp front-proxy fails to sanitize inbound X-Remote-* identity headers, allowing authenticated attackers to perform privilege escalation to system:masters and bypass multi-tenant authorization.","title":"Authentication Bypass and Privilege Escalation in kcp Front-Proxy","url":"https://feed.craftedsignal.io/briefs/2026-09-kcp-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Kcp-Dev","version":"https://jsonfeed.org/version/1.1"}