Kubernetes Middleware Pepr Vulnerability with Cluster-Admin RBAC Configuration
CVE-2026-23634

NONE

Key Information:

Status
Vendor
CVE Published:
16 January 2026

What is CVE-2026-23634?

Pepr, a type-safe middleware for Kubernetes, had a vulnerability due to its default cluster-admin RBAC configuration prior to version 1.0.5. This setting lacks explicit enforcement of least-privilege principles for module authors, allowing users to create resources dynamically without pre-configuration. While this enhances the onboarding experience for new users, it exposes clusters to potential security risks. The vulnerability has been addressed in version 1.0.5, which introduces improved RBAC capabilities to protect against inadvertently granting excessive permissions.

Affected Version(s)

pepr < 1.0.5

References

CVSS V3.1

Score:
Severity:
NONE
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.