CVE-2026-84199: Kyverno before 1.16.2 SSRF via APICall Feature

Published Sep 1, 2026
·
Updated

Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, so a user with namespace-level Policy creation permissions can direct Kyverno to make HTTP requests to arbitrary internal resources (e.g., cloud metadata endpoints such as 169.254.169.254 or other tenants' resources). Because Kyverno executes these requests using its cluster-wide high-privilege ServiceAccount (a Confused Deputy problem), the responses—potentially including other tenants' secrets and cloud IAM credentials—are returned in the PolicyReport and can be read by the attacker, breaking multi-tenant isolation.

Affected Software

1 affected component
Kyverno Kyverno<1.16.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Kyverno to a version that resolves this vulnerability.

    Fixed in 1.16.2
  2. Compensating control

    Mitigate the SSRF risk in the Kyverno APICall feature by preventing namespace-level users from creating Policies with ServiceCall configurations that include an unvalidated URL field; restrict Policy creation/ServiceCall permissions to trusted namespaces/users until Kyverno is upgraded to 1.16.2.

Event History

Sep 1, 2026
CVE Published
via MITRE·11:33 AM
Data Sourced
via MITRE·11:33 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this vulnerability?

A user who has permission to create namespace-level Kyverno Policies can exploit it. This is particularly significant in multi-tenant clusters, where such a user may use Kyverno's cluster-wide ServiceAccount privileges to access resources belonging to other tenants.

2

What access or conditions are required for exploitation?

The attacker needs namespace-level Policy creation permissions and must be able to configure a ServiceCall using the APICall feature. No user interaction is required; the attacker supplies an unvalidated URL that Kyverno then requests.

3

What can an attacker obtain through the SSRF?

Kyverno can be directed to request arbitrary internal HTTP resources, including cloud metadata endpoints or other tenants' resources. Responses are returned in PolicyReport data readable by the attacker, potentially exposing secrets or cloud IAM credentials.

4

How can I tell whether the issue affects my deployment?

Deployments running Kyverno before 1.16.2 are affected. Review whether namespace-level users or tenant roles can create Kyverno Policies with ServiceCall/APICall configurations, and inspect PolicyReports for unexpected results from such policies.

5

What should be prioritized if patching cannot happen immediately?

Restrict namespace-level permissions to create Kyverno Policies, especially Policies that can use ServiceCall/APICall. Treat PolicyReport access as sensitive because it may contain responses obtained using Kyverno's high-privilege ServiceAccount.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203