← All Advisories

Kyverno ClusterPolicy apiCall Attaches the Admission Controller Service Account Token to Outbound HTTP Requests Without Validating the Destination URL

Last refreshed2026-09-30

Status: UPDATED  |  Advisory ID: CVE-2026-41323

Key Details

CVECVE-2026-41323
CVSS Score / Version8.1 (High) / CVSS v3.1
Updated2026-06-17
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productskyverno kyverno
Classified asCWE-200 (Exposure of Sensitive Information to an Unauthorized Actor)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
kyvernokyverno
SubsystemsGeneral OT
SectorsMultiple

What to Know

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc1, and 1.16.4, Kyverno's apiCall feature in ClusterPolicy automatically attaches the admission controller's ServiceAccount token to outgoing HTTP requests. The service URL has no validation — it can point anywhere, including attacker-controlled servers. Since the admission controller SA has permissions to patch webhook configurations, a stolen token leads to full cluster compromise. Versions 1.18.0-rc1, 1.17.2-rc1, and 1.16.4 patch the issue. (NVD)

What to Do

Monitor kyverno's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-41323
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-41323
Vendor advisoryhttps://github.com/kyverno/kyverno/security/advisories/GHSA-f9g8-6ppc-pqq4