Kubernetes Multi-tenancy Framework Vulnerability in Capsule by Project Capsule
CVE-2026-65835
6.6MEDIUM
What is CVE-2026-65835?
A vulnerability in Capsule, a multi-tenancy framework for Kubernetes, allows Tenant Owners to bypass security controls. Versions 0.13.0 to 0.13.8 contain an oversight that prevents proper rejection of cluster-scoped resources by the controller client. Specifically, the ResourceReference.LoadResources and IsNamespacedGVK checks were not enforced for these users, enabling unauthorized creation of critical resources like ClusterRole or ValidatingWebhookConfiguration. This issue was resolved in version 0.13.8.
Affected Version(s)
capsule >= 0.13.0, < 0.13.8
