Kubernetes Multi-Cluster Management Panel Vulnerability in KubePi
CVE-2026-69129

5.8MEDIUM

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-69129?

KubePi, a multi-cluster management panel for Kubernetes, contains an authorization bypass vulnerability that affects versions up to 2.0.0. This issue allows authenticated users with cluster management permissions to access or modify data in clusters for which they do not have explicit authorization. Specifically, the cluster-scoped APIs fail to properly validate user access per cluster, potentially enabling unauthorized actions on cluster-specific data. This misconfiguration can be manipulated under certain role and cluster configurations, leading to unauthorized read or modify actions. The issue has been rectified in version 2.0.1.

Affected Version(s)

KubePi < 2.0.1

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.