Cross-Namespace Data Access Issue in Kyverno by the Vendor
CVE-2026-100703

8.3HIGH

Key Information:

Vendor

Kyverno

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100703?

Versions of Kyverno from 1.16.0 to 1.19.0 expose a vulnerability that permits unauthorized access to data across namespaces. The globalcontext.Lib library is registered in the policy environment without appropriate namespace restrictions. As a result, a tenant capable of creating namespaced policies can exploit this flaw to retrieve sensitive cached information from a cluster-scoped GlobalContextEntry, thus bypassing RBAC permissions and compromising the integrity of the environment. The issue was addressed in version 1.19.1.

Affected Version(s)

kyverno 1.16.0 < 1.19.1

kyverno 1.19.1

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

BrianWillows
.