Kubernetes Java Client Library Vulnerability Exposes File System to Compromised Pods
CVE-2026-15687

2.7LOW

Key Information:

Vendor

Kubernetes

Vendor
CVE Published:
23 July 2026

What is CVE-2026-15687?

A security concern has been identified in the Kubernetes Java client library, where a compromised pod could potentially create files in arbitrary locations on the host machine. This vulnerability arises when using copy operations via non-tar methods, specifically copyDirectoryFromPod, when the enableTarCompressing option is set to false. This flaw poses risks to the integrity of the system by allowing unauthorized file creation, which can lead to further exploitation.

Affected Version(s)

kubernetes-client/java 10.0.0 < 25.0.1

kubernetes-client/java 26.0.0

kubernetes-client/java 25.0.1

References

CVSS V3.0

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ibrahim el zein and Hasan Sheet
.