Cluster Admin for All: Critical Kyverno Flaw (CVSS 10) Shatters Isolation
ID: 438fa96d-3b70-5d51-98a7-c01de08f5974
STIX ID: report--438fa96d-3b70-5d51-98a7-c01de08f5974
Feed Name: securityonline.info
**Kyverno critical vulnerability and DoS patched:** Kyverno maintainers released fixes for CVE-2026-22039 (critical, CVSS 10) which allows any authenticated user with permission to create a namespaced Policy to cause the Kyverno admission controller to perform arbitrary Kubernetes API requests (enabling privilege escalation, data exfiltration, and cluster takeover), and CVE-2026-23881 (CVSS 7.7) which permits denial of service via exponential memory consumption; affected versions are <=1.16.2 and <=1.15.2 and patched versions v1.16.3 and v1.15.3 implement namespace enforcement and stricter validation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
