← Voltar à pesquisa de CVEs

CVE-2026-42541

Kubewarden

Descrição

Kubewarden is a policy engine for Kubernetes. Prior to , An attacker with privileged AdmissionPolicy or AdmissionPolicyGroup create permissions (which isn-t the default) can craft a policy that makes use of the can_i host callback. The callback issues a SubjectAccessReview (SAR) requests to enumerate RBAC permissions of any user or service account across the cluster. can_i does not perform that check to enforce the context-aware allow-list and forwards the request directly to the callback handler, which executes a real SubjectAccessReview using policy-server privileges. This creates a policy-level authorization gap: can_i is effectively usable even when the policy has no context-aware resource grant. This is an information disclosure / reconnaissance issue, and not direct workload data exfiltration. The attacker learns permission information, such as whether specific service accounts can -get secrets-, -create pods-, or -bind clusterroles- in chosen namespaces. This vulnerability is fi...

CVSS 4.3EPSS 0.17099999999999999%Risco 0.44
Ver fonte
Publicação
2026-05-12 18:17:24
Versões afetadas
unknown
Tipo
Core software
Vetor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N