Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jrey8343

#34067of 53,633
7.7Total CVSS
Vulnerabilities · 1
PT-2026-34843
7.7
2026-04-16
Kyverno · Kyverno · CVE-2026-41068
**Name of the Vulnerable Software and Affected Versions** Kyverno versions prior to 1.17.2 **Description** A flaw in the ConfigMap context loader allows for cross-namespace privilege escalation. The `configMap.namespace` field lacks validation, enabling a namespace administrator to read ConfigMaps from any namespace by leveraging Kyverno's privileged service account. This results in a complete Role-Based Access Control (RBAC) bypass in multi-tenant Kubernetes clusters. **Recommendations** Update to version 1.17.2.