Policy Bypass Vulnerability in Kyverno by Nirmata
CVE-2026-84200
9.4CRITICAL
What is CVE-2026-84200?
Kyverno versions v1.9.0 through v1.12.7 exhibit a flaw in policy exception handling. In this situation, if a policy configured in enforce mode collides with two PolicyExceptions, the less restrictive exception prevails. This allows an attacker to exploit the vulnerability by crafting a resource name that aligns with the naming pattern of the more permissive exception, potentially skirting around essential policies like those that prohibit hostPath volumes. The issue has been resolved in Kyverno v1.13.0.
Affected Version(s)
kyverno 0 < 1.13.0
kyverno 1.13.0
