SB2026080544 - Authorization bypass through user-controlled key in KubePi



SB2026080544 - Authorization bypass through user-controlled key in KubePi

Published: August 5, 2026

Security Bulletin ID SB2026080544
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-69129)

CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key

CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to access or modify cluster-specific data outside their intended cluster scope.

The vulnerability exists due to authorization bypass through user-controlled key in cluster management APIs when handling cluster management operations. A remote user can perform crafted cluster management requests to access or modify cluster-specific data outside their intended cluster scope.

Exploitation requires an authenticated account with cluster management permissions and depends on role assignments and managed cluster configuration.


Remediation

Install update from vendor's website.