Arbitrary File Read Vulnerability in KEDA by KEDA Core
CVE-2025-68476

8.2HIGH

Key Information:

Vendor

Kedacore

Status
Vendor
CVE Published:
22 December 2025

What is CVE-2025-68476?

KEDA, a Kubernetes-based Event Driven Autoscaling solution, has a vulnerability that affects the TriggerAuthentication resource used for HashiCorp Vault authentication. In versions before 2.17.3 and 2.18.3, improper path validation allows attackers with certain permissions to exploit this vulnerability. By manipulating requests, it is possible to exfiltrate sensitive files from the node's filesystem, which can include critical system information such as secrets and keys, posing significant risks to system integrity and confidentiality. The issue has been rectified in the latest versions.

Affected Version(s)

keda < 2.17.3 < 2.17.3

keda >= 2.18.0, < 2.18.3 < 2.18.0, 2.18.3

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.