CVE-2026-22039Disclosure(kyverno / kyverno)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch kyverno kyverno systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization boundary bypass in namespaced Kyverno Policy apiCall. The resolved `urlPath` is executed using the Kyverno admission controller ServiceAccount, with no enforcement that the request is limited to the policy’s namespace. As a result, any authenticated user with permission to create a namespaced Policy can cause Kyverno to perform Kubernetes API requests using Kyverno’s admission controller identity, targeting any API path allowed by that ServiceAccount’s RBAC. This breaks namespace isolation by enabling cross-namespace reads (for example, ConfigMaps and, where permitted, Secrets) and allows cluster-scoped or cross-namespace writes (for example, creating ClusterPolicies) by controlling the urlPath through context variable substitution. Versions 1.16.3 and 1.15.3 contain a patch for the vulnerability.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kyverno

Threat summary

  • Patch or workaround signal is available
  • 17 mentions across 11 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 16 signals
  • Disclosure: 11 classified signals
  • General: 3 classified signals
  • Peaked 10d ago at 4 mentions (2026-01-27); latest day: 1
  • 17 total mentions across 11 days

Affected systems

Vendors
Products
kyverno

Deep dive

Activity timeline17 mentions / 11d
01234Mentions · 2026-01-27: 4Mentions · 2026-01-28: 2Mentions · 2026-01-29: 1Mentions · 2026-01-31: 1Mentions · 2026-02-05: 1Mentions · 2026-02-11: 2Mentions · 2026-02-13: 2Mentions · 2026-03-22: 1Mentions · 2026-04-14: 1Mentions · 2026-04-25: 1Mentions · 2026-05-15: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-02-05: 1Patch / Workaround · 2026-03-22: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-01-27: 4Technical Details · 2026-01-28: 2Technical Details · 2026-01-29: 1Technical Details · 2026-01-31: 1Technical Details · 2026-02-11: 2Technical Details · 2026-02-13: 2Technical Details · 2026-03-22: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-25: 1Technical Details · 2026-05-15: 101-2701-2801-2901-3102-0502-1102-1303-2204-1404-2505-15
Signal classification3 categories
Disclosure
1164.7%
Patch
317.6%
General
317.6%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-01-274
Disclosure4
2026-01-282
Disclosure1Patch1
2026-01-291
Disclosure1
2026-01-311
Disclosure1
2026-02-051
Patch1
2026-02-112
General2
2026-02-132
Disclosure2
2026-03-221
Disclosure1
2026-04-141
Disclosure1
2026-04-251
General1
2026-05-151
Patch1
Full discourse17 posts
  • White Rabbitx@TheRabbitPy
    Disclosure

    🚨 CVE-2026-22039 (CVSS 9.9): Kyverno K8s policy engine <1.12.3 cluster‑role binding esc → full cluster control. K8s admins patch! https://cve.komodosec.com/cve-list?search=&cvss_score_range=9&year=&has_exploit=&results_per_page=15&sort=publish_date&order=asc

    Post summary

    The post announces a high‑severity (CVSS 9.9) vulnerability in Kyverno K8s policy engine versions below 1.12.3 that permits cluster‑role binding escape to full cluster control, and urges K8s administrators to patch immediately.

    0002067
    374 followersView on X
  • Ville Vesilehto@thevilledev
    Patch

    I reported and fixed a critical vulnerability in Kyverno (CVE-2026-22039) and @minimusio made a nice write-up about it: https://www.minimus.io/post/cve-2026-22039-how-kyvernos-critical-authorization-bypass-breaks-kubernetes-namespace-isolation

    Post summary

    The user reported and fixed a critical Kyverno vulnerability (CVE-2026-22039) and linked to a write‑up that details the issue.

    01010150
    44 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    Kyverno users: A cross-namespace privilege escalation (CVE-2026-22039) via policy apiCall has been identified. Update to mitigate this #Kyverno #Kubernetes #PrivilegeEscalation. https://www.pulsepatch.io/posts/cve-2026-22039-kyverno-cross-namespace-privilege-escalation

    Post summary

    A cross‑namespace privilege escalation vulnerability (CVE‑2026‑22039) in Kyverno has been discovered and users are advised to apply updates to mitigate the risk.

    1000097
    1 followersView on X
  • Israel@f1tym1
    Patch

    GHSA-cvq5-hhx3-f99p — Go: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) https://ift.tt/pNqPGZM Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) ### Summary CVE-2026-22039 fixed cross-namespace privi…

    Post summary

    The post announces CVE‑2026‑22039, a Kyverno RBAC isolation flaw, and notes that a patch has been released but is incomplete, indicating ongoing mitigation efforts.

    0000045
    971 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-41068 Kyverno is a policy engine designed for cloud native platform engineering teams. The patch for CVE-2026-22039 fixed cross-namespace privilege escalation in Kyverno's … https://www.cve.org/CVERecord?id=CVE-2026-41068

    Post summary

    The post briefly mentions CVE-2026-41068, referencing a patch for a related CVE and noting a privilege escalation flaw, but provides no exploitation or mitigation specifics.

    00000100
    57.2K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Kyverno, SSRF & Privilege Escalation, #CVE-2026-22039 (Critical) https://dailycve.com/kyverno-ssrf-privilege-escalation-cve-2026-22039-critical/

    Post summary

    The text announces a critical Kyverno vulnerability (SSRF and privilege escalation) identified as CVE‑2026‑22039 and provides a link to a detailed report.

    0000026
    181 followersView on X
  • 🐾 FAUN.dev()@joinFAUN
    Disclosure

    Kyverno - a CNCF policy engine for Kubernetes - just dropped a critical one: CVE-2026-22039. It lets limited-access users jump namespaces by hijacking Kyverno's cluster-wide ServiceAccount thro... https://www.minimus.io/post/cve-2026-22039-how-kyvernos-critical-authorization-bypass-breaks-kubernetes-namespace-isolation --- More tech like this—join us 👉 https://faun.dev/join

    Post summary

    The post announces a newly discovered critical authorization bypass in Kyverno that permits namespace hopping via hijacked ServiceAccounts, yet it offers no PoC, exploit, or patch information.

    0000046
    2.0K followersView on X
  • Kaptain - Kubernetes News, Tutorials & Tools@_FAUNKaptain_
    Disclosure

    Kyverno - a CNCF policy engine for Kubernetes - just dropped a critical one: CVE-2026-22039. It lets limited-access users jump namespaces by hijacking Kyverno's cluster-wide ServiceAccount thro... https://www.minimus.io/post/cve-2026-22039-how-kyvernos-critical-authorization-bypass-breaks-kubernetes-namespace-isolation --- More tech like this—join us 👉 https://faun.dev/join

    Post summary

    CVE-2026-22039 is a critical authorization bypass in Kyverno that lets limited‑access users hop between namespaces by hijacking the cluster‑wide ServiceAccount.

    0000039
    203 followersView on X
  • 🐾 FAUN.dev()@joinFAUN
    General

    New Kaptain is out — Kubernetes wins and warts. 🚨 Kyverno CVE-2026-22039: auth bypass 📏 In-place Pod resize (no restarts) 🩺 Node Readiness Controller ⚠️ Ingress NGINX retirement ⚡ GKE Inference Gateway cuts Vertex AI latency Read: http://from.faun.to/r/0bqk https://t.co/RvHFoNjpL4

    Post summary

    The tweet references Kyverno CVE-2026-22039 as an authentication bypass but offers no PoC, exploit code, patch, or evidence of active exploitation.

    0000081
    2.0K followersView on X
  • Kaptain - Kubernetes News, Tutorials & Tools@_FAUNKaptain_
    General

    New Kaptain is out — Kubernetes wins and warts. 🚨 Kyverno CVE-2026-22039: auth bypass 📏 In-place Pod resize (no restarts) 🩺 Node Readiness Controller ⚠️ Ingress NGINX retirement ⚡ GKE Inference Gateway cuts Vertex AI latency Read: http://from.faun.to/r/0bqk https://t.co/vbfh4cZyDe

    Post summary

    The tweet announces the new Kaptain release and notes the Kyverno CVE-2026-22039 auth bypass, but offers no further technical, exploit, or mitigation details.

    0000052
    203 followersView on X
  • Zero Day Wire@zerodaywire
    Disclosure

    🚨Critical Kyverno Vulnerability Allows Cluster Admin Takeover via Policy Abuse (CVE-2026-22039) 🔗 https://zerodaywire.com/article.html?slug=critical-kyverno-vulnerability-allows-cluster-admin-takeover-via-policy-abuse-cve-2026-22039 #cybersecurity #infosec #threatintel https://t.co/LsTYKDnw6E

    Post summary

    The post announces a critical Kyverno vulnerability (CVE‑2026‑22039) that can enable cluster admin takeover via policy abuse, but it provides no proof of concept, exploit code, active exploitation evidence, or remediation details.

    00000111
    141 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A cross-namespace privilege escalation vulnerability (CVE-2026-22039) affects Kyverno via policy apiCall. Review your #Kyverno policies and update. #Kubernetes #CloudNative https://www.pulsepatch.io/posts/cve-2026-22039-kyverno-privilege-escalation

    Post summary

    The tweet announces the cross-namespace privilege escalation vulnerability CVE-2026-22039 in Kyverno and urges users to review and update their policies, linking to a post with additional details.

    00000105
    1 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-22039: The Policeman's Backdoor: Escaping Namespaces in Kyverno (CVE-2026-22039) A critical authorization bypass and Server-Side Request Forgery (SSRF) vulnerability in Kyverno's policy engine allows restricted users to leverage the engine's ... https://cvereports.com/reports/CVE-2026-22039

    Post summary

    The report details a critical authorization bypass and SSRF flaw (CVE‑2026‑22039) in Kyverno’s policy engine, allowing namespace escape, but provides no PoC, exploit, or patch information.

    00000130
    29 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22039 Kyverno Policy Authorization Bypass Enables Cross-Namespace Kubernetes API Requests https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22039

    Post summary

    The text announces a new Kyverno policy authorization bypass (CVE‑2026‑22039) that allows cross‑namespace Kubernetes API requests.

    0000093
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-22039: CRITICAL] Critical security vulnerability in Kyverno versions < 1.16.3 and 1.15.3 allows bypassing authorization boundaries, leading to potential cross-namespace data access and API requests...#cve,CVE-2026-22039,#cybersecurity https://cvefind.com/CVE-2026-22039

    Post summary

    The tweet announces the critical CVE-2026-22039 in Kyverno, noting an authorization boundary bypass that could allow cross-namespace data access.

    0000074
    584 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-22039 - Critical Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization boundary bypass in namespaced Kyverno Po... https://www.thehackerwire.com/vulnerability/CVE-2026-22039/ https://t.co/IoypCX56Nq

    Post summary

    CVE‑2026‑22039 is a critical authorization boundary bypass affecting Kyverno versions before 1.16.3 and 1.15.3 – no exploit, patch, or active exploitation details are provided.

    0000098
    113 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-22039: Kyverno Cross-Namespace Privileg... Complete namespace isolation bypass in Kyverno lets any authenticated user pivot to Kyverno's ServiceAccount for arbitr... https://zerodaysignal.com/vulnerability/CVE-2026-22039 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    Kyverno’s namespace isolation bypass allows authenticated users to pivot to the Kyverno ServiceAccount, but no PoC, exploit, patch, or active exploitation is mentioned.

    0000070
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkyvernokyverno---

Explore more