CVE-2026-32768
Chall-Manager's invalid NetworkPolicy enables a malicious actor to pivot into another namespace
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
11th
Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. In versions prior to 0.6.5, due to a miswritten NetworkPolicy, a malicious actor can pivot from an instance to any Pod out of the origin namespace. This breaks the security-by-default property expected as part of the deployment program, leading to a potential lateral movement. In the specific case of sdk/kubernetes.Kompose it does not isolate the instances. This issue has been fixed in version 0.6.5.
| CWE | CWE-284 |
| Vendor | ctfer-io |
| Product | chall-manager |
| Published | Mar 20, 2026 |
| Last Updated | Mar 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for ctfer-io chall-manager
Be the first to know when new unknown vulnerabilities affecting ctfer-io chall-manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
ctfer-io / chall-manager
< 0.6.5