Missing Authentication for Critical Function in KubePi - CVE-2026-65956
Published: August 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to alter global SSO configuration, take over an administrator account, escalate privileges, or perform server-side requests.
The vulnerability exists due to missing authentication for critical function in the SSO configuration API endpoints and connectivity test functionality when handling SSO/OIDC/SAML management operations through publicly reachable routes. A remote attacker can send crafted requests to configuration and connectivity test endpoints to alter global SSO configuration, take over an administrator account, escalate privileges, or perform server-side requests.
Exploitation can affect the authentication process through exposed configuration read, write, and connectivity test operations.