{"id":"CVE-2026-100706","published":"2026-09-26T14:16:55.843","lastModified":"2026-09-28T15:20:06.633","description":"kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. Attackers can exploit this by using percent-encoded directory traversal sequences to create MutatingWebhookConfiguration objects cluster-wide or PolicyException objects in the kyverno namespace, enabling privilege escalation to cluster admin.","cvssScore":9.9,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-441"],"vendors":[],"products":[],"references":[{"url":"https://github.com/kyverno/kyverno/security/advisories/GHSA-5qq8-67g6-4h2w","tags":[]},{"url":"https://www.vulncheck.com/advisories/kyverno-before-1.19.1-privilege-escalation-via-policy-apicall-urlpath","tags":[]}],"exploitRefs":[{"url":"https://github.com/kyverno/kyverno/security/advisories/GHSA-5qq8-67g6-4h2w","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows namespace tenants to bypass per-namespace restrictions and create objects in other namespaces, leading to potential privilege escalation to cluster admin.","exploitability":"Exploitation is relatively straightforward given the ability to use percent-encoded directory traversal sequences, requiring attackers to have access to the affected kyverno version.","blast_radius":"If exploited, the impact could be severe, as it allows attackers to create cluster-wide objects, significantly increasing the attack surface.","remediation":"Upgrade to kyverno 1.19.1 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","privilege-escalation","kubernetes","policy-bypass"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:48:46.208Z"}}