Maintainers of Kyverno (a Kubernetes-native policy engine) released fixes for a critical authorization boundary bypass in namespaced Policy apiCall, tracked as CVE-2026-22039 (CVSS 10.0). The issue is that the resolved urlPath is executed using the Kyverno admission controller ServiceAccount without enforcing that the request remains within the policy’s namespace, allowing a user who can create a namespaced Policy to coerce Kyverno into making Kubernetes API requests with Kyverno’s own RBAC permissions. This breaks namespace isolation and can enable cross-namespace reads (including ConfigMaps and potentially Secrets) and cross-namespace or cluster-scoped writes by controlling urlPath via context variable substitution.
Impact includes potential privilege escalation to cluster-admin (e.g., by creating a RoleBinding in kube-system), data access across tenants, and cluster disruption (e.g., creating malicious ClusterPolicies). Affected versions are Kyverno prior to 1.16.3 and 1.15.3, with patches available in 1.16.3 and 1.15.3; reporting also notes an additional high-severity DoS issue addressed alongside the critical fix (CVE-2026-23881).

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting emphasized the CVSS 10.0 severity of CVE-2026-22039 and noted that the same Kyverno update also fixed CVE-2026-23881, a high-severity denial-of-service issue that could crash the engine through unbounded memory consumption. The report reiterated that affected versions were 1.16.2 and earlier and 1.15.2 and earlier.
Public advisories described CVE-2026-22039 as a critical Kyverno flaw that lets an authenticated user who can create a namespaced Policy coerce Kyverno into making Kubernetes API requests beyond the policy's namespace. The disclosures noted impacts including cross-namespace reads, possible cluster-scoped writes, and effective escalation toward cluster-admin privileges.
Kyverno maintainers released security updates 1.16.3 and 1.15.3 to fix CVE-2026-22039, a critical authorization boundary bypass in namespaced Policy apiCall handling. The patch adds stricter validation to prevent cross-namespace targeting and closes a path to privilege escalation via the admission controller ServiceAccount.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.