Threat Advisory

Kyverno Flaw Enables Privilege Escalation to Admin in Any Namespace

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Kyverno CVE-2026-54523 is a critical cross-namespace privilege escalation vulnerability identified in the Kyverno Kubernetes policy engine. The vulnerability allows users with limited permissions in a specific namespace to bypass namespace isolation controls and access or modify resources in other namespaces, potentially including highly privileged namespaces such as kube-system. The issue occurs due to improper authorization validation in Kyverno’s policy processing mechanism, enabling attackers to abuse Kyverno’s elevated privileges and perform unauthorized actions within the Kubernetes cluster. CVSS Score: 9.6 (Critical). Affected Versions: Kyverno versions 1.18.1 and earlier. Successful exploitation may lead to privilege escalation, unauthorized resource access, policy manipulation, and potential compromise of the Kubernetes environment.

RECOMMENDATION:

We recommend you to update Kyverno to version 1.18.2.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Kyverno CVE-2026-54523 is a critical cross-namespace privilege escalation vulnerability identified in the Kyverno Kubernetes policy engine. The vulnerability allows users with limited permissions in a specific namespace to bypass namespace isolation controls and access or modify resources in other namespaces, potentially including highly privileged namespaces such as kube-system. The issue occurs due to improper authorization validation in Kyverno’s policy processing mechanism, enabling attackers to abuse Kyverno’s elevated privileges and perform unauthorized actions within the Kubernetes cluster. CVSS Score: 9.6 (Critical). Affected Versions: Kyverno versions 1.18.1 and earlier. Successful exploitation may lead to privilege escalation, unauthorized resource access, policy manipulation, and potential compromise of the Kubernetes environment.

RECOMMENDATION:

We recommend you to update Kyverno to version 1.18.2.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu