OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100703

HIGH · CVSS 7.7 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Kyverno versions 1.16.0 to 1.19.0 are vulnerable due to improper confinement of the globalcontext.Lib CEL library, allowing tenants to access sensitive data from cluster-scoped GlobalContextEntries without appropriate RBAC permissions. This vulnerability could lead to unauthorized information disclosure, impacting the security of the Kubernetes environment. Organizations using affected versions of Kyverno should prioritize upgrading to version 1.19.1 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100703
Severity
HIGH
CVSS
7.7
EPSS
0.23%

Original NVD Description

Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment without confining it to the policy's namespace, unlike the sibling libraries (resource.Lib, http.Lib, configMap loader) which are handed the policy namespace. A tenant who can create a namespaced policy (e.g. NamespacedValidatingPolicy, and likewise the namespaced mutating, deleting, generating, and image-validating policy kinds) in their own namespace can call globalContext.get("<entry>", "") and receive the full cached contents of a cluster-scoped GlobalContextEntry, including data cached from namespaces the tenant has no RBAC permission to read. No admission validation rejects such calls. Fixed in 1.19.1.