Security Flaw in KubePi Multi-Cluster Management Panel Exposes SSO Configurations
CVE-2026-65956
What is CVE-2026-65956?
The KubePi multi-cluster management panel suffers from an authorization bypass in its Single Sign-On (SSO) configuration API endpoints. These endpoints are publicly accessible alongside the SSO login and callback interfaces, allowing unauthorized users to perform management operations without the need for administrator privileges. This vulnerability enables the potential for unauthorized inspection or alteration of global SSO configurations, which might lead to account takeovers or privilege escalations. Additionally, the SSO connectivity-test function can be exploited for server-side request forgery (SSRF) attacks. Furthermore, the user list API may leak sensitive authentication-related fields. This issue has been remedied in version 2.0.0.
Affected Version(s)
KubePi < 2.0.0
