Kubernetes Middleware Pepr Vulnerability with Cluster-Admin RBAC Configuration
CVE-2026-23634
NONE
What is CVE-2026-23634?
Pepr, a type-safe middleware for Kubernetes, had a vulnerability due to its default cluster-admin RBAC configuration prior to version 1.0.5. This setting lacks explicit enforcement of least-privilege principles for module authors, allowing users to create resources dynamically without pre-configuration. While this enhances the onboarding experience for new users, it exposes clusters to potential security risks. The vulnerability has been addressed in version 1.0.5, which introduces improved RBAC capabilities to protect against inadvertently granting excessive permissions.
Affected Version(s)
pepr < 1.0.5
