CVE-2026-84195 PUBLISHED

Kyverno before 1.16.4 Credential Leak via apiCall

Assigner: VulnCheck
Reserved: 01.09.2026 Published: 01.09.2026 Updated: 01.09.2026

Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate the token by directing apiCall requests to external or attacker-controlled endpoints, gaining full control over Kyverno policies and cluster resources.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
CVSS Score: 8.3

Product Status

Vendor kyverno
Product kyverno
Versions Default: unaffected
  • affected from 0 to 1.16.4 (excl.)
  • Version 1.16.4 is unaffected

Credits

  • scumfrog reporter

References

Problem Types

  • Exposure of Sensitive Information to an Unauthorized Actor CWE