CVE-2026-100707
Kyverno before 1.19.1 Namespace Isolation Bypass via Percent-Encoded Path
CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th
Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of namespaced Policy resources due to inconsistent path interpretation between validation and execution. A low-privilege tenant can use percent-encoded dot-segments in urlPath to bypass namespace checks and read resources from other namespaces using the Kyverno admission controller's ServiceAccount credentials.
| CWE | CWE-22 |
| Vendor | kyverno |
| Product | kyverno |
| Published | Sep 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for kyverno kyverno
Be the first to know when new high vulnerabilities affecting kyverno kyverno are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
kyverno / kyverno
0 < 1.19.1
References
Credits
๐ dhki