Namespace Isolation Bypass in Kyverno by Nirmata
CVE-2026-100707
8.3HIGH
What is CVE-2026-100707?
Kyverno versions prior to 1.19.1 are susceptible to a namespace isolation bypass due to inconsistent path interpretation in the apiCall context of namespaced Policy resources. This vulnerability allows a low-privilege tenant to exploit percent-encoded dot-segments in urlPath. By doing so, the tenant can bypass namespace checks and access resources from other namespaces using the ServiceAccount credentials of the Kyverno admission controller. This poses a significant risk to resource security in multi-tenant Kubernetes environments.
Affected Version(s)
kyverno 0 < 1.19.1
kyverno 1.19.1
