CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-39429 — kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kub...

·Source: NIST NVD

Updated:

Executive Summary

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by the root shard and has no authentication or authorization in place. This allows anyone who can access the root shard to read and write to the cache server. This vulnerability is fixed in 0.30.3 and 0.29.3.

Analysis

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by the root shard and has no authentication or authorization in place. This allows anyone who can access the root shard to read and write to the cache server. This vulnerability is fixed in 0.30.3 and 0.29.3. CVSS Score: 8.2. Published: 2026-04-08T21:16:59.313.

Indicators of Compromise (1)

CVE (1)
CVE-2026-39429
Source Attribution

Originally published by NIST NVD on Apr 8, 2026. Verified by: NIST.

Related Threats