Kubernetes Multi-Cluster Management Panel Vulnerability in KubePi
CVE-2026-69129
5.8MEDIUM
What is CVE-2026-69129?
KubePi, a multi-cluster management panel for Kubernetes, contains an authorization bypass vulnerability that affects versions up to 2.0.0. This issue allows authenticated users with cluster management permissions to access or modify data in clusters for which they do not have explicit authorization. Specifically, the cluster-scoped APIs fail to properly validate user access per cluster, potentially enabling unauthorized actions on cluster-specific data. This misconfiguration can be manipulated under certain role and cluster configurations, leading to unauthorized read or modify actions. The issue has been rectified in version 2.0.1.
Affected Version(s)
KubePi < 2.0.1
