CVE-2026-100703

Source
https://cve.org/CVERecord?id=CVE-2026-100703
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100703.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-100703
Aliases
  • GHSA-59v6-2x73-wfg4
Published
2026-09-26T13:23:58Z
Modified
2026-09-28T03:48:30Z
Severity
  • 8.3 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N CVSS Calculator
Summary
Kyverno before 1.19.1 Cross-Namespace Data Access via globalcontext.Lib
Details

Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment without confining it to the policy's namespace, unlike the sibling libraries (resource.Lib, http.Lib, configMap loader) which are handed the policy namespace. A tenant who can create a namespaced policy (e.g. NamespacedValidatingPolicy, and likewise the namespaced mutating, deleting, generating, and image-validating policy kinds) in their own namespace can call globalContext.get("", "") and receive the full cached contents of a cluster-scoped GlobalContextEntry, including data cached from namespaces the tenant has no RBAC permission to read. No admission validation rejects such calls. Fixed in 1.19.1.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-200"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100703.json"
}
References

Affected packages

Git / github.com/kyverno/kyverno

Affected ranges

Type
GIT
Repo
https://github.com/kyverno/kyverno
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "1.16.0"
        },
        {
            "fixed":  "1.19.1"
        },
        {
            "fixed":  "1.19.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100703.json"