OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-100706

CRITICAL · CVSS 9.9 EPSS 0.61% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Kyverno versions prior to 1.19.1 are vulnerable due to improper validation of URL-encoded path segments in the Policy apiCall urlPath, allowing namespace tenants to bypass restrictions and create objects in other namespaces. This vulnerability can be exploited using percent-encoded directory traversal sequences, potentially leading to privilege escalation to cluster admin through the creation of MutatingWebhookConfiguration objects or PolicyException objects. Organizations using Kyverno should prioritize patching to mitigate this critical risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100706
Severity
CRITICAL
CVSS
9.9
EPSS
0.61%

Original NVD Description

kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. Attackers can exploit this by using percent-encoded directory traversal sequences to create MutatingWebhookConfiguration objects cluster-wide or PolicyException objects in the kyverno namespace, enabling privilege escalation to cluster admin.