CVE-2026-41323

CRITICAL CVSS 3.1: 9.1 EPSS 0.57%
Updated Jun 17, 2026
Kyverno
Parameter Value
CVSS 9.1 (CRITICAL)
Affected Versions 1.17.0 — 1.17.2
Fixed In 1.16.4
Type CWE-200 (Information Exposure), CWE-918 (Server-Side Request Forgery (SSRF))
Vendor Kyverno
Public PoC No

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc1, and 1.16.4, Kyverno's apiCall feature in ClusterPolicy automatically attaches the admission controller's ServiceAccount token to outgoing HTTP requests. The service URL has no validation — it can point anywhere, including attacker-controlled servers.

Since the admission controller SA has permissions to patch webhook configurations, a stolen token leads to full cluster compromise. Versions 1.18.0-rc1, 1.17.2-rc1, and 1.16.4 patch the issue.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products 2

Configuration From (including) Up to (excluding)
Kyverno Kyverno
cpe:2.3:a:kyverno:kyverno:*:-:*:*:*:*:*:*
— 1.16.4
Kyverno Kyverno
cpe:2.3:a:kyverno:kyverno:*:*:*:*:*:*:*:*
1.17.0 1.17.2