GPU VulnDB

Database/Container, Kubernetes & orchestration

Kyverno: percent-encoded traversal in Policy apiCall urlPath escapes the namespace clamp to cluster admin

CVSS 9.4CVE-2026-100706Container, Kubernetes & orchestrationcurated

Impact

Kyverno before 1.19.1 does not decode URL-encoded path segments before applying the per-namespace clamp on a Policy's apiCall urlPath. A tenant who can create a namespaced Policy can use percent-encoded traversal to make the admission controller issue requests outside their namespace, acting with the controller's own ServiceAccount. That reaches cluster-scoped objects: creating a MutatingWebhookConfiguration lets the attacker intercept and rewrite every admission request in the cluster, and creating a PolicyException in the kyverno namespace disables the policies meant to constrain them. On a multi-tenant GPU cluster this is a direct path from one tenant namespace to cluster admin, which means any tenant's pods, any node's GPUs, and every secret the control plane holds.

Who can reach it

Any authenticated tenant with permission to create Policy objects in a namespace they control - the normal state of affairs where Kyverno is offered to tenants for their own guardrails. No cluster-level rights needed.

What to do

Upgrade Kyverno to 1.19.1 or later and roll the admission-controller deployment; this is a controller restart, no node disruption. Until then, remove tenant RBAC to create namespaced Policy/ClusterPolicy objects, and audit for MutatingWebhookConfigurations and for PolicyExceptions in the kyverno namespace that you did not create.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.