๐Ÿ” CVE Alert

CVE-2026-62246

HIGH 8.5

Kamaji: TenantControlPlane namespace/name collision binds two tenants to the same SQL datastore schema + DB user, breaking per-tenant isolation

CVSS Score
8.5
EPSS Score
0.0%
EPSS Percentile
0th

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and GetDefaultDatastoreUsername(), allowing distinct tenants with colliding normalized identifiers to share control-plane state and read, modify, or destroy another tenant's Kubernetes data. This issue is fixed in version 26.7.4-edge.

CWE CWE-284 CWE-653
Vendor clastix
Product kamaji
Published Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for clastix kamaji

Be the first to know when new high vulnerabilities affecting clastix kamaji are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

clastix / kamaji
< 26.7.4-edge

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/clastix/kamaji/security/advisories/GHSA-4f3f-65vx-r34f github.com: https://github.com/clastix/kamaji/commit/4232a9df7ccd08075c26191f59566202042543a9