CVE-2026-65956

Source
https://cve.org/CVERecord?id=CVE-2026-65956
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-65956.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-65956
Aliases
  • GHSA-wjrh-4j52-c664
Published
2026-08-26T22:40:55.741Z
Modified
2026-08-30T03:30:19.896632088Z
Severity
  • 10.0 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover and SSRF
Details

KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endpoints are exposed on the same public routing boundary as the SSO login and callback endpoints, so SSO, OIDC, and SAML management operations can be reached without administrator authorization. Because reading, creating, and updating the global SSO configuration is not restricted to administrators, an unauthorized or low-privileged user can inspect or alter the authentication configuration, which under certain conditions can lead to account takeover or privilege escalation. The SSO connectivity-test function can additionally be abused as a server-side request forgery primitive, and the user list API returns user objects without consistently clearing authentication-related fields. This issue is fixed in version 2.0.0.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65956.json",
    "cwe_ids": [
        "CWE-306"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/1panel-dev/kubepi

Affected ranges

Type
GIT
Repo
https://github.com/1panel-dev/kubepi
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.0.0"
        }
    ]
}

Affected versions

v1.*
v1.0.0
v1.0.1
v1.1.0
v1.2.0
v1.2.1
v1.5.0
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.7.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-65956.json"