CCB Alert@CCBalertDisclosure
The post warns of a critical scope bypass (CVE-2026-22806) in vCluster Platform with CVSS 9.1 that allows limited access keys to reach unauthorized resources, but does not mention a PoC, exploit tools, active exploitation, or a patch.
PulsePatch.io@pulsepatchioDisclosure
The post warns Loft vCluster Platform users about CVE‑2026‑22806, a critical access key flaw that could grant out‑of‑scope access, and recommends reviewing access controls.
CVEFind.com@CveFindComPatch
The post informs that vCluster Platform versions 4.6.0, 4.5.4, 4.4.2, and 4.3.10 have patched a critical access‑key scope bypass flaw and provides mitigation guidance.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text announces a disclosure of CVE‑2026‑22806, an access‑key scope bypass vulnerability affecting vCluster Platform versions prior to 4.6.0.
CVE@CVEnewGeneral
The text indicates that CVE-2026-22806 affects earlier versions of the vCluster Platform (4.6.0, 4.5.4, 4.4.2, and 4.3.10) and links to the CVE record, but provides no additional exploitation, mitigation, or technical detail.
The Hacker Wire@TheHackerWireGeneral
The tweet announces a critical CVE (CVE-2026-22806) but only links to an external article; it contains no PoC, exploit details, patch information, or technical specifics.
0day Signal@0dayPublishingDisclosure
The post announces that vCluster Platform’s access keys suffer a scope bypass that allows attackers to obtain full tenant access rights.