Authorization bypass through user-controlled key in KubePi - CVE-2026-69129
Published: August 5, 2026
Vulnerability details
The vulnerability allows a remote user to access or modify cluster-specific data outside their intended cluster scope.
The vulnerability exists due to authorization bypass through user-controlled key in cluster management APIs when handling cluster management operations. A remote user can perform crafted cluster management requests to access or modify cluster-specific data outside their intended cluster scope.
Exploitation requires an authenticated account with cluster management permissions and depends on role assignments and managed cluster configuration.