CVE-2026-41068: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)

Published Apr 24, 2026
·
Updated

Kyverno is a policy engine designed for cloud native platform engineering teams. The patch for CVE-2026-22039 fixed cross-namespace privilege escalation in Kyverno's apiCall context by validating the URLPath field. However, the ConfigMap context loader has the identical vulnerability — the configMap.namespace field accepts any namespace with zero validation, allowing a namespace admin to read ConfigMaps from any namespace using Kyverno's privileged service account. This is a complete RBAC bypass in multi-tenant Kubernetes clusters. An updated fix is available in version 1.17.2.

Affected Software

2 affected components
Kyverno Kyverno<1.17.2
Kyverno Kyverno<1.17.2

Event History

Apr 24, 2026
CVE Published
via MITRE·03:14 AM
Data Sourced
via MITRE·03:14 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 AM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-41068?

CVE-2026-41068 has been assigned a high severity rating due to its potential for cross-namespace read access that bypasses RBAC isolation in Kyverno.

2

How do I fix CVE-2026-41068?

To fix CVE-2026-41068, update Kyverno to version 1.17.3 or later, which addresses the vulnerability.

3

Who is affected by CVE-2026-41068?

Users of Kyverno versions up to 1.17.2 are affected by CVE-2026-41068 due to the vulnerability in cross-namespace read access.

4

What is the impact of CVE-2026-41068?

The impact of CVE-2026-41068 is that it allows unauthorized users to read resources across namespace boundaries, undermining role-based access control.

5

Is CVE-2026-41068 a result of another vulnerability?

Yes, CVE-2026-41068 is an incomplete fix for CVE-2026-22039, which initially addressed cross-namespace privilege escalation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203