Critical Kyverno flaw could allow Kubernetes tenants to gain cluster administrator access
A critical security vulnerability in Kyverno could allow users with limited permissions in a Kubernetes namespace to escalate their privileges and potentially gain cluster administrator access.
Tracked as CVE-2026-100706, the vulnerability affects Kyverno versions before 1.19.1 and has been assigned a CVSS score of 9.9, placing it in the critical severity category.
Kyverno is a policy engine for Kubernetes that allows administrators to create and enforce policies governing resources running within Kubernetes clusters.
The vulnerability is caused by insufficient validation of URL-encoded path segments used by the `apiCall` functionality within Kyverno policies.
According to the vulnerability disclosure, a tenant with permission to create a namespaced Kyverno Policy could use specially crafted, percent-encoded directory traversal sequences to bypass Kyverno’s intended namespace restrictions.
This could allow operations to be performed outside the attacker’s authorised namespace using the privileges of the Kyverno admission-controller service account.
In particular, an attacker could potentially create `MutatingWebhookConfiguration` objects at the cluster level or create `PolicyException` objects within the Kyverno namespace.
Such access could ultimately allow an attacker to escalate their privileges to cluster administrator level, giving them significantly greater control over workloads and resources running within the Kubernetes environment.
The vulnerability is particularly relevant to shared or multi-tenant Kubernetes environments where users or applications have permission to create Kyverno policies within their own namespaces.
Kyverno has addressed the problem in version 1.19.1. Organisations running an earlier release are advised to upgrade to the fixed version or later.
Security teams should also review which users and service accounts are permitted to create Kyverno Policy resources and ensure that these permissions are limited to those that require them.
CVE-2026-100706 was publicly recorded on 26 September 2026. The vulnerability information indicates that the underlying issue had already been addressed by Kyverno 1.19.1 before the CVE record was published.
The vulnerability is currently not listed as a CISA Known Exploited Vulnerability, according to available vulnerability database information.
Administrators using Kyverno should check their deployed version and upgrade to 1.19.1 or later, particularly where untrusted or lower-privileged users are able to create Kyverno policies.
The disclosure highlights the risks of namespace isolation failures in Kubernetes environments, where a vulnerability in a policy or admission-control component can potentially cross security boundaries and affect the wider cluster.

Blogger at www.systemtek.co.uk
