Kubernetes Java Client Library Vulnerability Exposes File System to Compromised Pods
CVE-2026-15687
2.7LOW
What is CVE-2026-15687?
A security concern has been identified in the Kubernetes Java client library, where a compromised pod could potentially create files in arbitrary locations on the host machine. This vulnerability arises when using copy operations via non-tar methods, specifically copyDirectoryFromPod, when the enableTarCompressing option is set to false. This flaw poses risks to the integrity of the system by allowing unauthorized file creation, which can lead to further exploitation.
Affected Version(s)
kubernetes-client/java 10.0.0 < 25.0.1
kubernetes-client/java 26.0.0
kubernetes-client/java 25.0.1