PT-2026-24144 · Unknown · Kubewarden

Thevilledev

·

Published

2026-03-09

·

Updated

2026-05-13

·

CVE-2026-29773

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kubewarden versions prior to 1.33.0
Description Kubewarden is a policy engine for Kubernetes. An attacker with privileged "AdmissionPolicy" create permissions could leverage three deprecated host-callback APIs: kubernetes/ingresses, kubernetes/namespaces, and kubernetes/services. By crafting a policy that utilizes these APIs, an attacker gains read access to Ingresses, Namespaces, and Services resources. This access is read-only, with no write capabilities and no access to sensitive data like Secrets or ConfigMaps. The attacker could potentially reveal cluster internal topology by reading Service information, and access namespace names and labels, and Ingress hostnames and routing rules.
Recommendations Update the policy-server image used by PolicyServers to version 1.33.0. Alternatively, temporarily reduce the permissions of users to prevent them from creating or updating namespaced AdmissionPolicies or AdmissionPolicyGroups.

Exploit

Fix

LPE

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-29773
GHSA-6R7F-3FWQ-HQ74
GO-2026-4652
SUSE-SU-2026:1042-1

Affected Products

Kubewarden