PT-2026-44722 · Capsule · Capsule

Xy585

·

Published

2026-05-28

·

Updated

2026-06-16

·

CVE-2026-30963

CVSS v3.1

3.9

Low

VectorAV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Capsule versions prior to 0.13.0
Description Capsule uses a webhook to validate update requests targeting namespaces to prevent namespace hijacking. However, the webhook fails to define interception rules for the 'namespace/finalize' and 'namespace/status' subresource APIs. Since these APIs can modify the metadata field of a namespace, a tenant administrator with permissions to modify these subresources can successfully perform namespace hijacking by altering the ownerReferences variable.
Recommendations Update to version 0.13.0. As a temporary mitigation, add the 'namespaces', 'namespaces/status', and 'namespace/finalize' subresources to the resources list in the ValidatingWebhookConfiguration rules.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-30963
GHSA-2WW6-HF35-MFJM
GO-2026-5043

Affected Products

Capsule