CVE-2026-22806Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to versions 4.6.0, 4.5.4, 4.4.2, and 4.3.10, when an access key is created with a limited scope, the scope can be bypassed to access resources outside of it. However, the user still cannot access resources beyond what is accessible to the owner of the access key. Versions 4.6.0, 4.5.4, 4.4.2, and 4.3.10 fix the vulnerability. Some other mitigations are available. Users can limit exposure by reviewing access keys which are scoped and ensuring any users with access to them have appropriate permissions set. Creating automation users with very limited permissions and using access keys for these automation users can be used as a temporary workaround where upgrading is not immediately possible but scoped access keys are needed.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 5 mentions (2026-01-29); latest day: 2
  • 7 total mentions across 2 days

Deep dive

Activity timeline7 mentions / 2d
01345Mentions · 2026-01-29: 5Mentions · 2026-01-30: 2Patch / Workaround · 2026-01-29: 1Technical Details · 2026-01-29: 3Technical Details · 2026-01-30: 201-2901-30
Signal classification3 categories
Disclosure
457.1%
General
228.6%
Patch
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-01-295
Disclosure2General2Patch1
2026-01-302
Disclosure2
Full discourse7 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical Scope Bypass in #vCluster Platform. #CVE-2026-22806 CVSS: 9.1. This flaw allows limited access keys to bypass restrictions and access unauthorized resources! #Kubernetes #Patch #Patch #Patch

    Post summary

    The post warns of a critical scope bypass (CVE-2026-22806) in vCluster Platform with CVSS 9.1 that allows limited access keys to reach unauthorized resources, but does not mention a PoC, exploit tools, active exploitation, or a patch.

    01000296
    7.2K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Loft vCluster Platform users: CVE-2026-22806 is a critical access key vulnerability allowing access beyond scope. Review access control configurations. #Loft #vCluster #Kubernetes https://www.pulsepatch.io/posts/cve-2026-22806-loft-vcluster-platform-access-key-scope-bypass

    Post summary

    The post warns Loft vCluster Platform users about CVE‑2026‑22806, a critical access key flaw that could grant out‑of‑scope access, and recommends reviewing access controls.

    0000043
    1 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-22806: CRITICAL] vCluster Platform versions 4.6.0, 4.5.4, 4.4.2, and 4.3.10 fix a vulnerability where access key scope could be bypassed in managing virtual clusters. Mitigations include reviewing ...#cve,CVE-2026-22806,#cybersecurity https://cvefind.com/CVE-2026-22806

    Post summary

    The post informs that vCluster Platform versions 4.6.0, 4.5.4, 4.4.2, and 4.3.10 have patched a critical access‑key scope bypass flaw and provides mitigation guidance.

    0000062
    584 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22806 Access Key Scope Bypass Vulnerability in vCluster Platform Before 4.6.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22806

    Post summary

    The text announces a disclosure of CVE‑2026‑22806, an access‑key scope bypass vulnerability affecting vCluster Platform versions prior to 4.6.0.

    0000042
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-22806 vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to versions 4.6.0, 4.5.4, 4.4.2, and 4.3.10,… https://www.cve.org/CVERecord?id=CVE-2026-22806

    Post summary

    The text indicates that CVE-2026-22806 affects earlier versions of the vCluster Platform (4.6.0, 4.5.4, 4.4.2, and 4.3.10) and links to the CVE record, but provides no additional exploitation, mitigation, or technical detail.

    00000175
    56.5K followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🔴 CVE-2026-22806 - Critical vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to versions 4.6.0, 4.5.4, 4.4.2, and 4.3.10, when an access key i... https://www.thehackerwire.com/vulnerability/CVE-2026-22806/ https://t.co/bGffQPY1Ub

    Post summary

    The tweet announces a critical CVE (CVE-2026-22806) but only links to an external article; it contains no PoC, exploit details, patch information, or technical specifics.

    0000059
    113 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-22806: vCluster Platform's Access Keys ... Scope bypass in vCluster Platform's access keys gives attackers full tenant access rights despite permission boundaries... https://zerodaysignal.com/vulnerability/CVE-2026-22806 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces that vCluster Platform’s access keys suffer a scope bypass that allows attackers to obtain full tenant access rights.

    0000065
    132 followersView on X

Explore more