Kubernetes Multi-tenancy Framework Vulnerability in Capsule by Project Capsule
CVE-2026-61672
7.1HIGH
What is CVE-2026-61672?
The Capsule framework, designed for multi-tenancy in Kubernetes, contains a flaw in its ForbiddenListSpec.ExactMatch implementation prior to version 0.13.7. This issue arises when the sorting mechanism for denied metadata keys is case-insensitive, leading to potential discrepancies between byte-order sorting and the actual key formats. As a result, authenticated tenant owners could exploit this misconfiguration to bypass namespace, Service, or delegated node metadata restrictions. Consequently, attackers can influence critical cluster policies, network exposure, or scheduling processes outside their designated tenant boundaries. It is important to upgrade to version 0.13.7 to mitigate this risk.
Affected Version(s)
capsule < 0.13.7
