Privilege Escalation Vulnerability in Kyverno by Nirmata
CVE-2026-100706
9.4CRITICAL
What is CVE-2026-100706?
The Kyverno policy engine prior to version 1.19.1 contains a vulnerability that inadequately validates URL-encoded path segments within the Policy apiCall urlPath parameter. This flaw allows unauthorized namespace tenants to bypass restrictions imposed by the per-namespace clamp, effectively enabling them to create objects across different namespaces using percent-encoded directory traversal sequences. An attacker could exploit this vulnerability to create MutatingWebhookConfiguration objects that operate cluster-wide or generate PolicyException objects within the Kyverno namespace. This exploitation could ultimately lead to unauthorized privilege escalation to cluster administrator rights.
Affected Version(s)
kyverno 0 < 1.19.1
kyverno 1.19.1
