๐Ÿ” CVE Alert

CVE-2026-84200

CRITICAL 9.0

Kyverno before v1.13.0 Policy Bypass via Multiple Exceptions

CVSS Score
9.0
EPSS Score
0.0%
EPSS Percentile
0th

Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive exception takes precedence, allowing an attacker to bypass the policy by crafting a resource name that matches the second exception's name pattern (e.g., '*ingress*'). This can be used to circumvent policies such as one blocking hostPath volumes. Fixed in v1.13.0.

CWE CWE-284
Vendor kyverno
Product kyverno
Published Sep 1, 2026
Stay Ahead of the Next One

Get instant alerts for kyverno kyverno

Be the first to know when new critical vulnerabilities affecting kyverno kyverno are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

kyverno / kyverno
0 < 1.13.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kyverno/kyverno/security/advisories/GHSA-gg4x-fgg2-h9w9 vulncheck.com: https://www.vulncheck.com/advisories/kyverno-before-1.13.0-policy-bypass-via-multiple-exceptions

Credits

๐Ÿ” r0binak