Authorization bypass through user-controlled key in KubePi - CVE-2026-69129

 

Authorization bypass through user-controlled key in KubePi - CVE-2026-69129

Published: August 5, 2026


Vulnerability identifier: #VU140980
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-69129
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access or modify cluster-specific data outside their intended cluster scope.

The vulnerability exists due to authorization bypass through user-controlled key in cluster management APIs when handling cluster management operations. A remote user can perform crafted cluster management requests to access or modify cluster-specific data outside their intended cluster scope.

Exploitation requires an authenticated account with cluster management permissions and depends on role assignments and managed cluster configuration.


Affected software

KubePi

How to mitigate CVE-2026-69129

Install security update from vendor's website.

KubePi - update to 2.0.1

External References