PT-2026-31352 · Kcp · Kcp

Published

2026-04-08

·

Updated

2026-04-08

·

CVE-2026-39429

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions kcp versions prior to 0.30.3 and prior to 0.29.3
Description Prior to versions 0.30.3 and 0.29.3, the cache server in kcp is directly exposed by the root shard without authentication or authorization. This allows anyone who can access the root shard to read and write to the cache server. An attacker can read all replicated resources from the cache, including RBAC data, cluster topology, API surfaces, admission control configurations, tenancy information, and cache metadata. A race condition exists that could allow temporary privilege escalation through full CRUD operations on the cache server, although practical exploitability is low. The replication controller acts as a self-healing mechanism, deleting injected objects almost instantly.
Recommendations Upgrade to kcp version 0.30.3 or later. Upgrade to kcp version 0.29.3 or later.

Fix

Missing Authentication

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-39429
GHSA-3J3Q-WP9X-585P

Affected Products

Kcp