BIT-kyverno-2026-41323

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/kyverno/BIT-kyverno-2026-41323.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-kyverno-2026-41323
Aliases
Published
2026-04-28T10:46:29Z
Modified
2026-09-08T08:48:08Z
Summary
Kyverno: ServiceAccount token leaked to external servers via apiCall service URL
Details

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0, 1.17.2, and 1.16.4, Kyverno's apiCall feature in ClusterPolicy automatically attaches the admission controller's ServiceAccount token to outgoing HTTP requests. The service URL has no validation — it can point anywhere, including attacker-controlled servers. Since the admission controller SA has permissions to patch webhook configurations, a stolen token leads to full cluster compromise. Versions 1.18.0, 1.17.2, and 1.16.4 patch the issue.

Database specific
{
    "cpes": [
        "cpe:2.3:a:kyverno:kyverno:*:*:*:*:*:go:*:*"
    ],
    "severity": "Critical"
}
References

Affected packages

Bitnami / kyverno

Package

Name
kyverno
Purl
pkg:bitnami/kyverno

Severity

  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.16.4
Introduced
1.17.0
Fixed
1.17.2

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/kyverno/BIT-kyverno-2026-41323.json"