---
cve: "CVE-2026-100707"
severity: "HIGH"
cvss: 8.3
epss: "0.5%"
vendor: "kyverno"
kev: false
exploited: false
published: "2026-09-26 14:16:55"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-29T03:21:04+02:00"
---

# CVE-2026-100707

> 8.3 HIGH · 🧪 PoC

## Beschreibung

Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of namespaced Policy resources due to inconsistent path interpretation between validation and execution. A low-privilege tenant can use percent-encoded dot-segments in urlPath to bypass namespace checks and read resources from other namespaces using the Kyverno admission controller's ServiceAccount credentials.

## CNA-Record (Kanon, cvelistV5)

- CNA: **VulnCheck**
- State: PUBLISHED
- Stand: 2026-09-28 17:41:14
- CNA-CVSS: **8.3** (`CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **poc**
  - Automatable: **no**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |

## Patch verfügbar (OSV)

- 40ec788d48bb28d83dbf85538e962a59db9d45c6 (Commit)

## BSI-Hinweise (deutsch)

- [Kyverno: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3285) — _BSI-Einstufung: hoch_
  Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Kyverno ausnutzen, um Sicherheitsmaßnahmen zu umgehen, SSRF auszuführen, vertrauliche Informationen offenzulegen, Daten zu manipulieren und unter bestimmten Umständen seine Berechtigungen auf Cluster-Administrator zu erweitern.

## Referenzen

- <https://github.com/kyverno/kyverno/security/advisories/GHSA-c5qq-7g2q-cpqp>
- <https://www.vulncheck.com/advisories/kyverno-before-1.19.1-namespace-isolation-bypass-via-percent-encoded-path>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-100707) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
