No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 28 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 26 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment without confining it to the policy's namespace, unlike the sibling libraries (resource.Lib, http.Lib, configMap loader) which are handed the policy namespace. A tenant who can create a namespaced policy (e.g. NamespacedValidatingPolicy, and likewise the namespaced mutating, deleting, generating, and image-validating policy kinds) in their own namespace can call globalContext.get("<entry>", "") and receive the full cached contents of a cluster-scoped GlobalContextEntry, including data cached from namespaces the tenant has no RBAC permission to read. No admission validation rejects such calls. Fixed in 1.19.1. | |
| Title | Kyverno before 1.19.1 Cross-Namespace Data Access via globalcontext.Lib | |
| First Time appeared |
Kyverno
Kyverno kyverno |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:kyverno:kyverno:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kyverno
Kyverno kyverno |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-28T17:42:15.793Z
Reserved: 2026-09-26T02:39:50.973Z
Link: CVE-2026-100703
Updated: 2026-09-28T17:42:11.270Z
Status : Awaiting Analysis
Published: 2026-09-26T14:16:55.420
Modified: 2026-09-28T18:17:15.880
Link: CVE-2026-100703
No data.
OpenCVE Enrichment
Updated: 2026-09-26T19:45:08Z