logo

Cluster Admin for All: Critical Kyverno Flaw (CVSS 10) Shatters Isolation

ID: 438fa96d-3b70-5d51-98a7-c01de08f5974

STIX ID: report--438fa96d-3b70-5d51-98a7-c01de08f5974

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-01-30

Date Updated: 2026-04-23

Author: Ddos

...
...

**Kyverno critical vulnerability and DoS patched:** Kyverno maintainers released fixes for CVE-2026-22039 (critical, CVSS 10) which allows any authenticated user with permission to create a namespaced Policy to cause the Kyverno admission controller to perform arbitrary Kubernetes API requests (enabling privilege escalation, data exfiltration, and cluster takeover), and CVE-2026-23881 (CVSS 7.7) which permits denial of service via exponential memory consumption; affected versions are <=1.16.2 and <=1.15.2 and patched versions v1.16.3 and v1.15.3 implement namespace enforcement and stricter validation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.