External risk intelligence

Kyverno Policy apiCall Path Traversal Privilege Escalation

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-100706

Kyverno is a Kubernetes admission controller that operates within an internal cluster environment. It is not designed to be exposed directly to the public internet; access is typically restricted to authorized cluster users and internal platform components, making public internet exposure uncommon.

Path Traversal

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Kyverno could allow unauthorized users to bypass security controls and create objects in unintended namespaces, potentially leading to privilege escalation. This issue arises from improper validation of URL-encoded path segments in the Policy API.

  • Namespace tenants could gain broader access.
  • It enables privilege escalation to cluster admin.
  • Confirm if Kyverno is in use and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker with authenticated access to a Kubernetes cluster could exploit a flaw in Kyverno's handling of URL-encoded path segments. By crafting a malicious request that targets the `apiCall` feature, an attacker could bypass namespace restrictions. This bypass would allow them to create sensitive cluster-wide configurations or objects within the Kyverno namespace, ultimately leading to elevated privileges.

  • Authenticated access within the cluster.
  • Crafted API request with encoded path segments.
  • Privilege escalation to cluster administrator.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow authenticated users with limited privileges to bypass namespace restrictions and create objects cluster-wide, potentially leading to elevated access. The impact is contingent on the Kyverno admission controller's configuration and the specific permissions granted to the admission controller's ServiceAccount.

  • Cluster-wide object creation is at risk.
  • Malicious URL-encoded path segments could be used.
  • Privilege escalation to cluster admin is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts the Kyverno admission controller, a component integral to Kubernetes security. Ownership likely falls to the platform or Kubernetes administration team responsible for managing the cluster's security posture and admission controllers. The initial step is to confirm if Kyverno is deployed, assess its exposure within the cluster, and identify the specific workloads or configurations that might be vulnerable.

  • Platform/Kubernetes Admin team ownership.
  • Verify Kyverno deployment and reachability.
  • Plan cluster-wide remediation during maintenance.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Kyverno?

Kyverno is an admission controller for Kubernetes that manages policies. It enforces security standards by validating, mutating, or generating resources automatically when they are created or updated within the cluster. It helps administrators ensure that workloads follow specific configurations and security best practices before they are ever permitted to run.

What is the vulnerability in CVE-2026-100706?

This CVE involves a weakness known as Improper Validation of Path Traversal, classified as CWE-441. In Kyverno, the software fails to properly check URL-encoded path segments within policy apiCall configurations. Because of this, an authenticated user can manipulate path strings to bypass intended security boundaries and interact with parts of the Kubernetes API they should not be able to access.

How can an attacker trigger this CVE-2026-100706 flaw?

An attacker must already have authenticated access to the Kubernetes cluster to attempt this. They trigger the flaw by submitting a crafted request using percent-encoded directory traversal sequences. Crucially, simple or standard API requests that do not use these specific URL-encoded sequences do not trigger the bypass, and users without existing cluster access cannot reach this logic.

Is my cluster at risk according to Halo Surface Signal?

Halo Surface Signal considers active exploitation unlikely because Kyverno is an internal component designed to operate within the cluster network, not exposed to the public internet. The primary risk exists if you have untrusted or malicious users already holding authorized access to your cluster, allowing them to interact with the Kyverno admission controller directly.

What steps should I take if I use Kyverno?

First, verify which versions of Kyverno are running in your environment. Since this issue is resolved in version 1.19.1, you should prioritize planning an upgrade if you are on an earlier release. Coordinate with your platform or Kubernetes administration team to assess your current policy configurations and ensure your admission controller is running an updated, secure version.

References