GPU VulnDB

Database/Container, Kubernetes & orchestration

Kyverno: namespaced policies can read cluster-scoped GlobalContextEntry data from other namespaces

CVSS 8.3CVE-2026-100703Container, Kubernetes & orchestrationcurated

Impact

Kyverno registers the globalcontext.Lib CEL library in the policy environment without scoping it to the policy's own namespace, unlike resource.Lib, http.Lib and the configMap loader, which are handed the namespace. A tenant permitted to create a namespaced policy in their own namespace - NamespacedValidatingPolicy and the namespaced mutating, deleting, generating and image-validating kinds - can call globalContext.get("<entry>", "") and get back the whole cached contents of a cluster-scoped GlobalContextEntry, including data cached from namespaces their RBAC does not cover. Nothing in admission validation rejects the call. On a shared GPU cluster where tenants are given namespace-local policy authoring, this is a direct cross-tenant read of whatever the platform team cached globally - registry credentials fetched over http, licence or entitlement data, cluster inventory - through a component installed to enforce isolation rather than break it.

Who can reach it

Any authenticated tenant with RBAC to create a namespaced Kyverno policy object in a namespace they control. No cluster-admin access and no access to the target namespaces is needed; the admission controller reads on their behalf.

What to do

Upgrade Kyverno to 1.19.1 or later, which scopes the library to the policy namespace, and restart the admission controller deployment to pick it up. Until then, revoke tenant permission to create the namespaced policy kinds, or stop caching sensitive data in cluster-scoped GlobalContextEntry objects. Cost is a controller rollout, not node maintenance - but note that restarting Kyverno briefly affects admission for the whole cluster, so do it with the webhook failure policy in mind.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.