CVE-2026-4789Disclosure(kyverno / kyverno)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch kyverno kyverno systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Kyverno, versions 1.16.0 and later, are vulnerable to SSRF due to unrestricted CEL HTTP functions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kyverno

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-31); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
kyverno

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-30: 1Mentions · 2026-03-31: 2Mentions · 2026-04-02: 1Patch / Workaround · 2026-04-02: 1Technical Details · 2026-03-31: 2Technical Details · 2026-04-02: 103-3003-3104-02
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-301
General1
2026-03-312
Disclosure2
2026-04-021
Patch1
Full discourse4 posts
  • Misbar | مسبار@MisbarSec
    Patch

    📌 ثغرة Kyverno SSRF غير المُصححة التي تُحوّل السياسات إلى أبواب خلفية على مستوى المجموعات تم الكشف عن ثغرة حرجة من نوع Server-Side Request Forgery (SSRF) في Kyverno، محرك السياسات مفتوح المصدر لبيئات Kubernetes، والمُشار إليها بـ CVE-2026-4789. تسمح هذه الثغرة للمهاجمين باستغلال سياسات Kyverno لتحويلها إلى أبواب خلفية على نطاق المجموعة، مما يمكنهم من تجاوز حواجز الأمان الأساسية. يُتيح هذا الاستغلال تنفيذ طلبات داخلية غير مصرح بها، مهدداً سلامة البنية التحتية لـ Kubernetes. يُنصح بمراقبة إعلانات CERT/CC والمطورين عن كثب لتوافر التصحيحات وتطبيقها فوراً لمعالجة هذا الخطر الأمني الجسيم. 🔗 للمزيد: https://securityonline.info/kyverno-ssrf-vulnerability-cve-2026-4789-kubernetes-security/ #امن_المعلومات #الامن_السيبراني #تقنية

    Post summary

    The message highlights a critical SSRF flaw in Kyverno, emphasizes the need to apply forthcoming patches, and provides technical details of the vulnerability.

    0003043
    245 followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    Kyverno (CVE-2026-4789) faces an unpatched SSRF flaw in its CEL HTTP functions, allowing attackers to bypass K8s namespaces. Secure your cluster now! #Kyverno #Kubernetes #K8s #CyberSecurity #InfoSec #SSRF #CloudNative #Vulnerability #CloudSecurity https://securityonline.info/kyverno-ssrf-vulnerability-cve-2026-4789-kubernetes-security/ https://t.co/oEoLFKXiHL

    Post summary

    The tweet announces that Kyverno has an unpatched SSRF flaw (CVE‑2026‑4789) that lets attackers bypass Kubernetes namespaces and urges immediate cluster hardening.

    00010254
    11.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4789 Kyverno, versions 1.16.0 and later, are vulnerable to SSRF due to unrestricted CEL HTTP functions. https://www.cve.org/CVERecord?id=CVE-2026-4789

    Post summary

    The post announces CVE-2026-4789, highlighting an SSRF vulnerability in Kyverno versions 1.16.0 and later caused by unrestricted CEL HTTP functions, with no PoC, exploit, or patch information provided.

    00010119
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4789 - CVE-2026-4789 Intel Report: https://ift.tt/lskrPxd

    Post summary

    Alert references CVE-2026-4789 but offers no detailed information beyond a link.

    0000041
    280 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkyvernokyverno---

Explore more