Server-Side Request Forgery in Kyverno Affects Kubernetes Security
CVE-2026-84196

8.3HIGH

Key Information:

Vendor

Kyverno

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-84196?

Kyverno versions prior to 1.18.0 are susceptible to a server-side request forgery (SSRF) vulnerability. This weakness allows authenticated users to exploit the apiCall.service.url endpoint, enabling them to inject user-controlled input through variable substitution. As a result, attackers can issue arbitrary HTTP requests targeting internal services, cloud metadata endpoints, and loopback addresses. The reflected response data in admission error messages facilitates non-blind data exfiltration, posing serious security risks for organizations relying on Kyverno for their Kubernetes security policies.

Affected Version(s)

kyverno 0 < 1.18.0

kyverno 1.18.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

scumfrog
.