CVE-2026-61682
9.9 CRITICALpublic exploit availablePublished 2026-09-18 · Updated 2026-09-24
AI risk analysis
- Summary
- The flaw allows cross-workspace impersonation and authorization bypass, enabling arbitrary resource manipulation.
- Exploitability
- Exploitation is relatively straightforward for any authenticated tenant with write access to identity headers.
- Blast radius
- Real-world impact is high, allowing full control over resources across workspaces.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to kcp version 0.31.4 or 0.32.2.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* identity headers before forwarding requests to shards. Any authenticated tenant can inject X-Remote-Group: system:masters, authorization.kcp.io/warrant, authentication.kcp.io/scopes, or a group used for per-workspace required-group gating, and the shard trusts these values as authenticated identity assertions. This allows cross-workspace impersonation, authorization bypass, and arbitrary reading, writing, or deletion of resources, secrets, RBAC data, APIExports, APIBindings, and LogicalClusters. This issue is fixed in versions 0.31.4 and 0.32.2.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-290, CWE-302, CWE-348
Public exploit & PoC references
- https://github.com/kcp-dev/kcp/commit/7437cdcfec8f927d1a9bf1b2dd1e075d038e27ca
- https://github.com/kcp-dev/kcp/commit/f913ee890fb2fd9fa78e50c43474b078bfb6aeff
- https://github.com/kcp-dev/kcp/releases/tag/v0.31.4
- https://github.com/kcp-dev/kcp/releases/tag/v0.32.2
- https://github.com/kcp-dev/kcp/security/advisories/GHSA-c8w2-fgvx-vhv4
All references
- https://github.com/kcp-dev/kcp/commit/7437cdcfec8f927d1a9bf1b2dd1e075d038e27ca
- https://github.com/kcp-dev/kcp/commit/f913ee890fb2fd9fa78e50c43474b078bfb6aeff
- https://github.com/kcp-dev/kcp/releases/tag/v0.31.4
- https://github.com/kcp-dev/kcp/releases/tag/v0.32.2
- https://github.com/kcp-dev/kcp/security/advisories/GHSA-c8w2-fgvx-vhv4
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-10059
- HIGHCVE-2026-100623PoC
- CRITICALCVE-2026-100706PoC
- CRITICALCVE-2026-17472
- HIGHCVE-2026-62182PoC
- HIGHCVE-2026-62371PoC
- HIGHCVE-2026-73553PoC
- HIGHCVE-2026-92574
Related by shared AI tags and CWE weakness class. Browse the full archive.