CVE-2026-22806

Source
https://cve.org/CVERecord?id=CVE-2026-22806
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22806.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-22806
Aliases
  • GHSA-c539-w4ch-7wxq
Published
2026-01-29T19:54:37.810Z
Modified
2026-01-30T02:56:21.924848Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
vCluster Platform's Access Keys Allows Access Beyond Scope
Details

vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to versions 4.6.0, 4.5.4, 4.4.2, and 4.3.10, when an access key is created with a limited scope, the scope can be bypassed to access resources outside of it. However, the user still cannot access resources beyond what is accessible to the owner of the access key. Versions 4.6.0, 4.5.4, 4.4.2, and 4.3.10 fix the vulnerability. Some other mitigations are available. Users can limit exposure by reviewing access keys which are scoped and ensuring any users with access to them have appropriate permissions set. Creating automation users with very limited permissions and using access keys for these automation users can be used as a temporary workaround where upgrading is not immediately possible but scoped access keys are needed.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22806.json",
    "cwe_ids": [
        "CWE-863"
    ]
}
References

Affected packages

Git / github.com/loft-sh/loft

Affected ranges

Type
GIT
Repo
https://github.com/loft-sh/loft
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "4.3.10"
        }
    ]
}
Type
GIT
Repo
https://github.com/loft-sh/loft
Events
Database specific
{
    "versions": [
        {
            "introduced": "4.4.0"
        },
        {
            "fixed": "4.4.2"
        }
    ]
}
Type
GIT
Repo
https://github.com/loft-sh/loft
Events
Database specific
{
    "versions": [
        {
            "introduced": "4.5.3"
        },
        {
            "fixed": "4.5.3"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22806.json"