Critical Alert 2 Active Exploits Detected Today

CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability →
CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability →
Powered by CVE Watchtower
×
September 1, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-84200NVD

Vulnerability Summary

Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive exception takes precedence, allowing an attacker to bypass the policy by crafting a resource name that matches the second exception's name pattern (e.g., '*ingress*'). This can be used to circumvent policies such as one blocking hostPath volumes. Fixed in v1.13.0.
Severity Level
CRITICAL(9.0)
Published Date
Sep 1, 2026
Last Modified
Sep 1, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
N/A
CVSS v3.1 Base Metrics
Attack VectorAdjacent
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh