Kyverno: NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system
Published Aug 26, 2026
9.6
CRITICALCVSS 3.1
EPSS 0.47%
Description
Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, allowing a namespace-scoped policy to invoke generator.apply(namespace, resources) with an arbitrary target namespace. The validation in pkg/cel/policies/mpol/validate.go checks that the policy compiles but does not enforce namespace scope, and GenerateResources in pkg/cel/libs/context.go does not reject the cross-namespace target. A user who can create NamespacedMutatingPolicy objects in one namespace can cause the admission controller, operating with cluster-wide privileges, to create ConfigMaps, NetworkPolicies, Secrets, RoleBindings, and other resources in another namespace, enabling unauthorized modification and potential privilege escalation. This issue is fixed in version 1.18.2.
Affected products
-
Affected
- ≥ 1.18.0, < 1.18.2
No data.
No data.
No Red Hat product state for this CVE.
github.com/kyverno/kyverno
Go
Introduced 1.18.0 Fixed 1.18.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/kyverno/kyverno | 1.18.0 | 1.18.2 |
Remediation
Red Hat statement
This Important vulnerability in Kyverno allows for privilege escalation due to improper validation of namespace arguments in NamespacedMutatingPolicy objects. However, Red Hat products, including Konflux components, are not affected by this flaw as the vulnerable code is not present in their deployments.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (12)
- https://access.redhat.com/security/cve/CVE-2026-54523 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2524413 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-66561 Advisory
- https://github.com/advisories/GHSA-79gf-7frw-68m9 Advisory
- https://github.com/kyverno/kyverno/commit/0919553c0ea1904f8d891280c92018da97946a06 x_refsource_MISC
- https://github.com/kyverno/kyverno/commit/5164bcdeda5b57678bc2d7a03ecc2cbb02982dae x_refsource_MISC
- https://github.com/kyverno/kyverno/pull/16238 x_refsource_MISC
- https://github.com/kyverno/kyverno/releases/tag/v1.18.2 x_refsource_MISC
- https://github.com/kyverno/kyverno/security/advisories/GHSA-79gf-7frw-68m9 exploitx_refsource_CONFIRM
- https://github.com/kyverno/sdk/commit/6573937441443e1ba5af9fbb28d5c0f20297f9df x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-54523
- https://www.cve.org/CVERecord?id=CVE-2026-54523
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-54523 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2524413 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-66561 | Advisory | |
| https://github.com/advisories/GHSA-79gf-7frw-68m9 | Advisory | |
| https://github.com/kyverno/kyverno/commit/0919553c0ea1904f8d891280c92018da97946a06 | x_refsource_MISC | |
| https://github.com/kyverno/kyverno/commit/5164bcdeda5b57678bc2d7a03ecc2cbb02982dae | x_refsource_MISC | |
| https://github.com/kyverno/kyverno/pull/16238 | x_refsource_MISC | |
| https://github.com/kyverno/kyverno/releases/tag/v1.18.2 | x_refsource_MISC | |
| https://github.com/kyverno/kyverno/security/advisories/GHSA-79gf-7frw-68m9 | exploitx_refsource_CONFIRM | |
| https://github.com/kyverno/sdk/commit/6573937441443e1ba5af9fbb28d5c0f20297f9df | x_refsource_MISC | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-54523 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-54523 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub