SEPTEMBER 12, 2026
Live Feed
Back to database
Case File

CVE-2026-15738

HIGH · CVSS 8.5 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

The Amazon AWS Load Balancer Controller prior to version 3.4.2 contains a vulnerability in the Gateway API listener-rule generation that allows an authenticated remote user to potentially intercept, spoof, or deny gRPC traffic across namespaces on a shared Gateway by manipulating HTTPRoute resources. This could lead to significant disruptions in service and unauthorized access to sensitive data. Organizations utilizing this controller should prioritize upgrading to the latest version to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15738
Severity
HIGH
CVSS
8.5
EPSS
0.37%

Original NVD Description

Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2 might allow an authenticated remote user to intercept, spoof, or deny another namespace's gRPC traffic on a shared Gateway via a crafted HTTPRoute resource. To mitigate this issue, users should upgrade to version 3.4.2.