Kyverno SSRF: Breaking Kubernetes Namespace Isolation (CVE-2026-4789)

A critical SSRF (Server-Side Request Forgery, where an attacker tricks a server into making HTTP requests on their behalf) vulnerability affects Kyverno versions 1.16.0 and later. Users with namespace-scoped permissions can make arbitrary HTTP requests from the Kyverno admission controller pod, bypassing Kubernetes RBAC entirely. This enables access to internal cluster services, cross-namespace data theft, […]

The post Kyverno SSRF: Breaking Kubernetes Namespace Isolation (CVE-2026-4789) appeared first on Orca Security.

原始链接: https://orca.security/resources/blog/kyverno-ssrf-vulnerability-cve-2026-4789/
侵权请联系站方: [email protected]

相关推荐

换一批