Kubernetes Multi-tenancy Framework Vulnerability in Capsule by Project Capsule
CVE-2026-65835

6.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-65835?

A vulnerability in Capsule, a multi-tenancy framework for Kubernetes, allows Tenant Owners to bypass security controls. Versions 0.13.0 to 0.13.8 contain an oversight that prevents proper rejection of cluster-scoped resources by the controller client. Specifically, the ResourceReference.LoadResources and IsNamespacedGVK checks were not enforced for these users, enabling unauthorized creation of critical resources like ClusterRole or ValidatingWebhookConfiguration. This issue was resolved in version 0.13.8.

Affected Version(s)

capsule >= 0.13.0, < 0.13.8

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.