CVE-2026-53487

Summary

Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated Kite users with any role can request /api/v1/overview for a cluster that their roles do not permit by selecting that cluster with x-cluster-name. The overview route is registered before middleware.RBACMiddleware() and GetOverview only checks len(user.Roles) > 0, so it returns aggregate Kubernetes inventory and capacity data from unauthorized clusters. Version 0.12.3 fixes the issue.

Affected Software

VendorProductVersion RangeStatus
kite-orgkite< 0.12.3affected

Weaknesses

  • CWE-862: CWE-862: Missing Authorization

References