CVE-2026-40868Disclosure(kyverno / kyverno)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 1.16.4, kyverno’s apiCall servicecall helper implicitly injects Authorization: Bearer ... using the kyverno controller serviceaccount token when a policy does not explicitly set an Authorization header. Because context.apiCall.service.url is policy-controlled, this can send the kyverno serviceaccount token to an attacker-controlled endpoint (confused deputy). Namespaced policies are blocked from servicecall usage by the namespaced urlPath gate in pkg/engine/apicall/apiCall.go, so this report is scoped to ClusterPolicy and global context usage. This vulnerability is fixed in 1.16.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-922

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kyverno

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-21); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
kyverno

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-21: 1Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 104-2104-2204-23
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-211
General1
2026-04-221
Disclosure1
2026-04-231
Disclosure1
Full discourse3 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    A service account token leak in `Kyverno` (CVE-2026-40868) via implicit bearer token injection impacts `apicall`/`servicecall`. Review `Kyverno` permissions. #Kubernetes #CloudNative #infosec https://www.pulsepatch.io/posts/cve-2026-40868-kyverno-token-leak

    Post summary

    The post announces a new Kyverno token leak vulnerability (CVE-2026-40868) that enables implicit bearer token injection, noting affected functions but providing no PoC, exploit code, active exploitation claims, or patch details.

    0000049
    12 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40868 Unauthorized Token Disclosure in Kyverno apiCall Service Prior to 1.16.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40868

    Post summary

    The post announces CVE-2026-40868, describing an unauthorized token disclosure flaw in Kyverno's apiCall Service before version 1.16.4, and links to a standard vulnerability details page.

    0000047
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40868 Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 1.16.4, kyverno’s apiCall servicecall helper implicitly injects Authorizatio… https://www.cve.org/CVERecord?id=CVE-2026-40868

    Post summary

    The post briefly references CVE-2026-40868 concerning Kyverno's apiCall servicecall helper prior to version 1.16.4 but provides no PoC, exploit details, or patch information, offering only a minimal note of the issue.

    00000141
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkyvernokyverno---

Explore more