CVE-2026-27112Patch(akuity / kargo)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch akuity kargo systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Kargo manages and automates the promotion of software artifacts. From 1.7.0 to before v1.7.8, v1.8.11, and v1.9.3, the batch resource creation endpoints of both Kargo's legacy gRPC API and newer REST API accept multi-document YAML payloads. Specially crafted payloads can manifest a bug present in the logic of both endpoints to inject arbitrary resources (of specific types only) into the underlying namespace of an existing Project using the API server's own permissions when that behavior was not intended. Critically, an attacker may exploit this as a vector for elevating their own permissions, which can then be leveraged to achieve remote code execution or secret exfiltration. Exfiltrated artifact repository credentials can be leveraged, in turn, to execute further attacks. In some configurations of the Kargo control plane's underlying Kubernetes cluster, elevated permissions may additionally be leveraged to achieve remote code execution or secret exfiltration using kubectl. This can reduce the complexity of the attack, however, worst case scenarios remain entirely achievable even without this. This vulnerability is fixed in v1.7.8, v1.8.11, and v1.9.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kargo

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-20); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
kargo

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-20: 2Mentions · 2026-02-21: 1Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-02-21: 1Technical Details · 2026-02-20: 1Technical Details · 2026-02-21: 102-2002-21
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-202
Disclosure1Patch1
2026-02-211
Patch1
Full discourse3 posts
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: CVE-2026-27112 in akuity kargo lets attackers inject resources & escalate privileges via API, risking RCE & secret leaks. Patch to 1.7.8/1.8.11/1.9.3+ now! 🔒 https://radar.offseq.com/threat/cve-2026-27112-cwe-863-incorrect-authorization-in--0476694e #OffSeq #CyberS... https://t.co/rVqx0lMRFY

    Post summary

    The tweet alerts about CVE‑2026‑27112 in Akuity Kargo, noting privilege escalation and RCE risk via API, and lists specific patch versions to mitigate the issue.

    0000037
    265 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27112 Kargo manages and automates the promotion of software artifacts. From 1.7.0 to before v1.7.8, v1.8.11, and v1.9.3, the batch resource creation endpoints of both Kargo… https://www.cve.org/CVERecord?id=CVE-2026-27112

    Post summary

    The message is a basic CVE record announcement for CVE-2026-27112 with no additional exploitation or mitigation details.

    0000090
    56.4K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    An authorization bypass (CVE-2026-27112) affects `Kargo`'s Batch Resource Creation API. Update `http://github.com/akuity/kargo` to 1.9.3 or later. #Kubernetes #CloudNative #Security https://www.pulsepatch.io/posts/cve-2026-27112-kargo-authorization-bypass

    Post summary

    A new authorization bypass vulnerability (CVE-2026-27112) in Kargo’s API is announced, and users are advised to upgrade to version 1.9.3 or later.

    0000033
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appakuitykargo-kubernetes-

Explore more