CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-100706 — kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Po...

·Source: NIST NVD

Updated:

Executive Summary

kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. Attackers can exploit this by using percent-encoded directory traversal sequences to create MutatingWebhookConfiguration objects cluster-wide or PolicyExc

Analysis

kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. Attackers can exploit this by using percent-encoded directory traversal sequences to create MutatingWebhookConfiguration objects cluster-wide or PolicyException objects in the kyverno namespace, enabling privilege escalation to cluster admin. CVSS Score: 9.9. Published: 2026-09-26T14:16:55.843.

Indicators of Compromise (1)

CVE (1)
CVE-2026-100706
Source Attribution

Originally published by NIST NVD on Sep 26, 2026. Verified by: NIST.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-14378 — The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leadi...

The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by

CVE-2026-14378
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-86345 — A flaw was found in 389-ds-base. The server does not discard plaintext bytes alr...

A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a cl

CVE-2026-86345
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-103765 — Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in...

Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as tcp_data_port or re-create rpc_meta entries to redirect KV cache transfers to attacker-controlled listeners, or exhaust server

CVE-2026-103765
NIST NVD