Description
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* identity headers before forwarding requests to shards. Any authenticated tenant can inject X-Remote-Group: system:masters, authorization.kcp.io/warrant, authentication.kcp.io/scopes, or a group used for per-workspace required-group gating, and the shard trusts these values as authenticated identity assertions. This allows cross-workspace impersonation, authorization bypass, and arbitrary reading, writing, or deletion of resources, secrets, RBAC data, APIExports, APIBindings, and LogicalClusters. This issue is fixed in versions 0.31.4 and 0.32.2.
Published: 2026-09-18
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

kcp’s front‑proxy fails to remove inbound X‑Remote‑User, X‑Remote‑Group, and X‑Remote‑Extra‑* identity headers before passing a request to a shard. An authenticated tenant can therefore inject an X‑Remote‑Group header of system:masters or other privileged groups, as well as warrant, scope, or workspace‑specific gating groups. Because the shard trusts these headers as true identity assertions, the attacker is able to impersonate the system:masters group, bypass workspace authorisation controls, and arbitrarily read, write, or delete any resource, including secrets, RBAC objects, APIExports, APIBindings, and LogicalClusters.

Affected Systems

kcp by kcp‑dev, versions older than 0.31.4 and 0.32.2 are affected. These are Kubernetes‑like control planes that honour inbound identity headers for shard requests.

Risk and Exploitability

The vulnerability carried a CVSS score of 9.9, indicating critical severity. EPSS score of <1% indicates a very low probability of exploitation, but the lack of remediation in the KEV catalog suggests it may not yet be widely exploited. Inferred from the description, the attack vector is network‑based, requiring only an authenticated client to send crafted headers across the front‑proxy to a shard. Once the headers are accepted, the attacker can gain system‑wide privileges across multiple workspaces with zero additional effort. The high impact combined with the openness of the mechanism makes this a serious risk for any kcp deployment that has not applied the available fixes.

Generated by OpenCVE AI on September 19, 2026 at 17:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade kcp to version 0.31.4 or later, or to 0.32.2 if available; these releases contain the fix that strips the vulnerable headers.
  • Configure any ingress or reverse‑proxy that forwards requests to the front‑proxy to reject or strip X‑Remote‑* headers, preventing accidental injection of unauthorized identities.
  • Verify that only trusted internal services are allowed to set identity headers and disable any external client that may add X‑Remote‑* headers; review RBAC settings to ensure no privilege is granted via injected headers.

Generated by OpenCVE AI on September 19, 2026 at 17:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-c8w2-fgvx-vhv4 kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace
History

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Kcp-dev
Kcp-dev kcp
Vendors & Products Kcp-dev
Kcp-dev kcp

Fri, 18 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* identity headers before forwarding requests to shards. Any authenticated tenant can inject X-Remote-Group: system:masters, authorization.kcp.io/warrant, authentication.kcp.io/scopes, or a group used for per-workspace required-group gating, and the shard trusts these values as authenticated identity assertions. This allows cross-workspace impersonation, authorization bypass, and arbitrary reading, writing, or deletion of resources, secrets, RBAC data, APIExports, APIBindings, and LogicalClusters. This issue is fixed in versions 0.31.4 and 0.32.2.
Title kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace
Weaknesses CWE-290
CWE-302
CWE-348
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T20:50:17.494Z

Reserved: 2026-07-10T18:36:58.848Z

Link: CVE-2026-61682

cve-icon Vulnrichment

Updated: 2026-09-18T19:24:35.062Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T16:17:07.523

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-61682

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:15:04Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing

  • CWE-302

    Authentication Bypass by Assumed-Immutable Data

  • CWE-348

    Use of Less Trusted Source