Description
Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, allowing a namespace-scoped policy to invoke generator.apply(namespace, resources) with an arbitrary target namespace. The validation in pkg/cel/policies/mpol/validate.go checks that the policy compiles but does not enforce namespace scope, and GenerateResources in pkg/cel/libs/context.go does not reject the cross-namespace target. A user who can create NamespacedMutatingPolicy objects in one namespace can cause the admission controller, operating with cluster-wide privileges, to create ConfigMaps, NetworkPolicies, Secrets, RoleBindings, and other resources in another namespace, enabling unauthorized modification and potential privilege escalation. This issue is fixed in version 1.18.2.
Published: 2026-08-26
Score: 9.6 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a malicious NamespacedMutatingPolicy to be created in any namespace managed by the cluster. Because the generator.apply(namespace, resources) call is unvalidated, the admission controller can create ConfigMaps, NetworkPolicies, Secrets, RoleBindings, and other resources in an arbitrary target namespace, including critical namespaces such as kube‑system. This leads to unauthorized modification of resources and a potential privilege escalation vector for attackers with sufficient permissions to create policies.

Affected Systems

Kyverno policy engine, versions 1.18.0 and 1.18.1 are vulnerable. The issue has been fixed in version 1.18.2 and later releases.

Risk and Exploitability

With a CVSS score of 9.6 this vulnerability is considered critical. No EPSS score is currently available, and it is not listed in the CISA KEV catalog. The attack requires the ability to create a NamespacedMutatingPolicy in the cluster, a privilege that typically belongs to cluster administrators or users with edit access to the kyverno namespace. Once a malicious policy is introduced, the cluster‑wide admission controller will execute the policy and create resources in any namespace without further authorization checks.

Generated by OpenCVE AI on August 26, 2026 at 17:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Kyverno to version 1.18.2 or later, which removes the unvalidated namespace argument in generator.apply and enforces authorization checks.
  • If an upgrade cannot be performed immediately, restrict the creation of NamespacedMutatingPolicy objects by applying RBAC roles that allow only trusted users to create them, and monitor for unexpected resources in protected namespaces.
  • Implement network segmentation and least‑privilege access controls so that even if a malicious policy is deployed, the cluster administrator can limit the impact of unauthorized RoleBindings and other sensitive objects.

Generated by OpenCVE AI on August 26, 2026 at 17:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-79gf-7frw-68m9 Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system
History

Wed, 26 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Kyverno
Kyverno kyverno
Vendors & Products Kyverno
Kyverno kyverno

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, allowing a namespace-scoped policy to invoke generator.apply(namespace, resources) with an arbitrary target namespace. The validation in pkg/cel/policies/mpol/validate.go checks that the policy compiles but does not enforce namespace scope, and GenerateResources in pkg/cel/libs/context.go does not reject the cross-namespace target. A user who can create NamespacedMutatingPolicy objects in one namespace can cause the admission controller, operating with cluster-wide privileges, to create ConfigMaps, NetworkPolicies, Secrets, RoleBindings, and other resources in another namespace, enabling unauthorized modification and potential privilege escalation. This issue is fixed in version 1.18.2.
Title Kyverno: NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-26T15:06:37.284Z

Reserved: 2026-06-15T18:40:01.651Z

Link: CVE-2026-54523

cve-icon Vulnrichment

Updated: 2026-08-26T15:06:09.636Z

cve-icon NVD

Status : Received

Published: 2026-08-26T15:16:48.910

Modified: 2026-08-26T16:16:27.277

Link: CVE-2026-54523

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T19:30:05Z

Weaknesses