Skip to content
June 11, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Vulnerability Report
  • The Unpatched Kyverno SSRF Flaw That Turns Policies Into Cluster-Wide Backdoors
  • Vulnerability Report

The Unpatched Kyverno SSRF Flaw That Turns Policies Into Cluster-Wide Backdoors

Do Son March 31, 2026 2 minutes read
0
Kyverno SSRF Kubernetes Policy Engine Kyverno Privilege Escalation CVE-2026-22039
Add as a preferred
source on Google

A critical security boundary in Kubernetes environments has been compromised. A new vulnerability note from CERT/CC has detailed a Server-Side Request Forgery (SSRF) flaw in Kyverno, the popular open-source, Kubernetes-native policy engine. Identified as CVE-2026-4789, the vulnerability affects Kyverno versions 1.16.0 to the present and allows attackers to bypass namespace restrictions to probe internal network services.

Kyverno is a cornerstone of cluster security, functioning as a dynamic admission controller that validates, mutates, and generates configurations. Because it must intercept and modify API requests, it naturally operates with “high-level permissions,” making it a “critical component of the cluster’s security posture and trust boundary”.

The flaw resides in Kyverno’s CEL-based HTTP functions (specifically Get and Post). According to the vulnerability note:

“Unlike Kyverno’s resource library, which enforces namespace boundaries, the HTTP library at pkg/cel/libs/http/http.go performs no URL validation or scoping”.

With “no blocklists, namespace restrictions, or destination checks” in place, an attacker can use these policies to “issue arbitrary HTTP requests from the Kyverno admission controller pod”.

The impact of this SSRF is particularly severe because of where the requests originate. An attacker with only “namespace-level permissions” can create a malicious policy that triggers an internal HTTP request, captures the response, and exfiltrates the data through the policy’s own error messages.

Because the Kyverno admission controller “often has privileged network reachability across internal cluster services and cloud metadata APIs,” this flaw effectively allows for:

  • Cross-namespace data access.Exposure of sensitive metadata from cloud providers.
  • Unauthorized access to internal cluster services that would otherwise be shielded.

CERT/CC noted that they were “unable to reach the vendor to coordinate this vulnerability,” meaning a patch is currently unavailable.

Until an official fix is released, administrators are urged to implement the following mitigation strategies:

  • Destination Controls: Implement strict URL validation within the CEL HTTP library to block access to “link-local and cloud metadata address ranges”.
  • Allowlists: Limit outbound requests to only “approved in-cluster services”.
  • Network Policies: Apply “default deny network policies” to the Kyverno admission controller pod itself to prevent unauthorized egress.

Without these safeguards, the very tool meant to enforce Pod Security Standards could become the primary engine for a cluster-wide breach.

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. Cluster Admin for All: Critical Kyverno Flaw (CVSS 10) Shatters Isolation
  2. Critical CrewAI Vulnerabilities Allow RCE and Sandbox Escapes via Prompt Injection
  3. Critical 9.8 CVSS SpEL Injection and SSRF Flaws Hit Spring AI Framework

Do Son

Do Son (aka Ddos) is a seasoned news reporter, bringing over a decade of expertise to the forefront of cyber security and technology reporting. My work provides timely and insightful analysis of emerging trends and critical developments in these rapidly evolving sectors.

Tags: Admission Controller CERT/CC Cloud Metadata cloud-native CVE-2026-4789 infosec K8s Security Kubernetes Kyverno Namespace Bypass Policy Engine ssrf

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-49261CVSS 10.0
    MariaDB server is a community developed fork of MySQL server. Versions 10.6.1...
  • CVE-2026-48062CVSS 9.8
    ### Impact The `ext_in` upload validation rule checked the MIME-derived guessed extension...
  • CVE-2026-9648CVSS 9.1
    The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients...
  • CVE-2026-11839CVSS 9.9
    Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies...
  • CVE-2026-38581CVSS 9.8
    SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers...
  • CVE-2026-48039CVSS 9.1
    # Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token |...
  • CVE-2026-7852CVSS 9.8
    Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc....
  • CVE-2026-35273CVSS 9.8
    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates...
  • CVE-2026-46695CVSS 10.0
    Boxlite is a sandbox service that allows users to create lightweight virtual...
  • CVE-2026-46703CVSS 9.6
    Boxlite is a sandbox service that allows users to create lightweight virtual...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • GreatXML BitLocker Bypass: Public PoC Exploit Disclosed
  • Check Point VPN Vulnerability Exploited in the Wild with Ransomware Links
  • Weekly Threat Intelligence: June 1 to June 7, 2026
  • Cisco SD-WAN Vulnerability Exploited in the Wild with Root RCE Risks
  • Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.