← Back to search

CVE-2026-61682

9.9 CRITICALpublic exploit available

Published 2026-09-18 · Updated 2026-09-24

AI risk analysis

Summary
The flaw allows cross-workspace impersonation and authorization bypass, enabling arbitrary resource manipulation.
Exploitability
Exploitation is relatively straightforward for any authenticated tenant with write access to identity headers.
Blast radius
Real-world impact is high, allowing full control over resources across workspaces.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to kcp version 0.31.4 or 0.32.2.
auth-bypassrbackubernetesidentityworkspaces

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* identity headers before forwarding requests to shards. Any authenticated tenant can inject X-Remote-Group: system:masters, authorization.kcp.io/warrant, authentication.kcp.io/scopes, or a group used for per-workspace required-group gating, and the shard trusts these values as authenticated identity assertions. This allows cross-workspace impersonation, authorization bypass, and arbitrary reading, writing, or deletion of resources, secrets, RBAC data, APIExports, APIBindings, and LogicalClusters. This issue is fixed in versions 0.31.4 and 0.32.2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-290, CWE-302, CWE-348

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.