Cross-Namespace Data Access Issue in Kyverno by the Vendor
CVE-2026-100703
8.3HIGH
What is CVE-2026-100703?
Versions of Kyverno from 1.16.0 to 1.19.0 expose a vulnerability that permits unauthorized access to data across namespaces. The globalcontext.Lib library is registered in the policy environment without appropriate namespace restrictions. As a result, a tenant capable of creating namespaced policies can exploit this flaw to retrieve sensitive cached information from a cluster-scoped GlobalContextEntry, thus bypassing RBAC permissions and compromising the integrity of the environment. The issue was addressed in version 1.19.1.
Affected Version(s)
kyverno 1.16.0 < 1.19.1
kyverno 1.19.1
