Kubernetes Multi-tenancy Framework Vulnerability in Capsule by Project Capsule
CVE-2026-61672

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-61672?

The Capsule framework, designed for multi-tenancy in Kubernetes, contains a flaw in its ForbiddenListSpec.ExactMatch implementation prior to version 0.13.7. This issue arises when the sorting mechanism for denied metadata keys is case-insensitive, leading to potential discrepancies between byte-order sorting and the actual key formats. As a result, authenticated tenant owners could exploit this misconfiguration to bypass namespace, Service, or delegated node metadata restrictions. Consequently, attackers can influence critical cluster policies, network exposure, or scheduling processes outside their designated tenant boundaries. It is important to upgrade to version 0.13.7 to mitigate this risk.

Affected Version(s)

capsule < 0.13.7

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.