CVE-2026-84200
Kyverno before v1.13.0 Policy Bypass via Multiple Exceptions
CVSS Score
9.0
EPSS Score
0.0%
EPSS Percentile
0th
Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive exception takes precedence, allowing an attacker to bypass the policy by crafting a resource name that matches the second exception's name pattern (e.g., '*ingress*'). This can be used to circumvent policies such as one blocking hostPath volumes. Fixed in v1.13.0.
| CWE | CWE-284 |
| Vendor | kyverno |
| Product | kyverno |
| Published | Sep 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for kyverno kyverno
Be the first to know when new critical vulnerabilities affecting kyverno kyverno are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
kyverno / kyverno
0 < 1.13.0
References
Credits
๐ r0binak