Database/Container, Kubernetes & orchestration
Kyverno: namespaced policies can read cluster-scoped GlobalContextEntry data from other namespaces
Impact
Kyverno registers the globalcontext.Lib CEL library in the policy environment without scoping it to the policy's own namespace, unlike resource.Lib, http.Lib and the configMap loader, which are handed the namespace. A tenant permitted to create a namespaced policy in their own namespace - NamespacedValidatingPolicy and the namespaced mutating, deleting, generating and image-validating kinds - can call globalContext.get("<entry>", "") and get back the whole cached contents of a cluster-scoped GlobalContextEntry, including data cached from namespaces their RBAC does not cover. Nothing in admission validation rejects the call. On a shared GPU cluster where tenants are given namespace-local policy authoring, this is a direct cross-tenant read of whatever the platform team cached globally - registry credentials fetched over http, licence or entitlement data, cluster inventory - through a component installed to enforce isolation rather than break it.
Who can reach it
Any authenticated tenant with RBAC to create a namespaced Kyverno policy object in a namespace they control. No cluster-admin access and no access to the target namespaces is needed; the admission controller reads on their behalf.
What to do
Upgrade Kyverno to 1.19.1 or later, which scopes the library to the policy namespace, and restart the admission controller deployment to pick it up. Until then, revoke tenant permission to create the namespaced policy kinds, or stop caching sensitive data in cluster-scoped GlobalContextEntry objects. Cost is a controller rollout, not node maintenance - but note that restarting Kyverno briefly affects admission for the whole cluster, so do it with the webhook failure policy in mind.
References
Related entries
- Kyverno: a PolicyException meant to exempt one image disables image signature verification for the whole resourceCVE-2026-100704 · Kyverno ImageValidatingPolicy evaluator (PolicyException spec.images / spec.allowedValues ignored)High
- Kyverno: legacy apiCall path skips the egress blocklist, allowing SSRF to cloud metadata from the admission controllerCVE-2026-100705 · Kyverno admission controller (legacy apiCall service executor / GlobalContextEntry)High
- Kyverno: percent-encoded dot-segments in apiCall urlPath bypass namespace scoping in namespaced PoliciesCVE-2026-100707 · Kyverno admission controller (namespaced Policy apiCall urlPath validation)High
- docker-socket-proxy: CONTAINERS access lets any client export container filesystems and read filesCVE-2026-78122 · Tecnativa docker-socket-proxy (/containers read endpoints)High
- Kyverno: admission controller ServiceAccount token attached to outbound apiCall requests leaks to any endpointCVE-2026-84195 · Kyverno admission controller (apiCall service mode)High
- Kyverno: SSRF via apiCall.service.url lets authenticated users reach internal and metadata endpointsCVE-2026-84196 · Kyverno admission controller (apiCall.service.url variable substitution)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.