Policy Bypass Vulnerability in Kyverno by Nirmata
CVE-2026-84200

9.4CRITICAL

Key Information:

Vendor

Kyverno

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-84200?

Kyverno versions v1.9.0 through v1.12.7 exhibit a flaw in policy exception handling. In this situation, if a policy configured in enforce mode collides with two PolicyExceptions, the less restrictive exception prevails. This allows an attacker to exploit the vulnerability by crafting a resource name that aligns with the naming pattern of the more permissive exception, potentially skirting around essential policies like those that prohibit hostPath volumes. The issue has been resolved in Kyverno v1.13.0.

Affected Version(s)

kyverno 0 < 1.13.0

kyverno 1.13.0

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

r0binak
.