PT-2026-46125 · Unknown+1 · Enterprise Gateway+1
CVE-2026-44181
·
Published
2026-06-03
·
Updated
2026-07-16
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Enterprise Gateway (affected versions not specified)
Description
Server Side Template Injection (SSTI) occurs during the rendering of Kubernetes manifests when using Jinja2, a template engine for Python. By including template expressions in environment variables passed via API calls, an attacker can execute Python code and OS commands within the Enterprise Gateway service. This can lead to the theft of the Kubernetes service account token, allowing the attacker to access secrets, interfere with other Jupyter kernels, and potentially compromise the entire Kubernetes cluster by scheduling privileged pods or pods with
hostPath volume mounts.Technical details include:
- API Endpoint:
/api/kernels - Vulnerable Parameters:
KERNEL POD NAMEandKERNEL WORKING DIR(and otherKERNEL XXXvariables)
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Enterprise Gateway
Jinja2