CVE-2026-84200

Summary

Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive exception takes precedence, allowing an attacker to bypass the policy by crafting a resource name that matches the second exception's name pattern (e.g., 'ingress'). This can be used to circumvent policies such as one blocking hostPath volumes. Fixed in v1.13.0.

Affected Software

VendorProductVersion RangeStatus
kyvernokyverno0 < 1.13.0affected
kyvernokyverno1.13.0unaffected

Weaknesses

  • CWE-284: Improper Access Control

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: total

Additional References

References