Impact
The vulnerability in KubePi versions up to 1.6.15 allows unauthenticated users to access SSO, OIDC, and SAML configuration endpoints. An attacker can read, create, or modify global SSO settings without administrator authorization, which can lead to administrative account takeover or privilege escalation. Additionally, an unprotected connectivity‑test function can be used as a server‑side request forgery primitive, and the user list API exposes authentication‑related fields to anyone querying it.
Affected Systems
Affected products are 1Panel‑dev KubePi running any version through 1.6.15. The issue was fixed in release 2.0.0. Administrators should verify the running version against the release notes linked in the advisory.
Risk and Exploitability
This flaw carries a CVSS score of 10 and has no EPSS estimate available, but it is not listed in the CISA KEV catalog. The exposed API endpoints are reachable over the public network boundary, meaning the attack vector is remote. An attacker with minimal or no privileges can exploit the configuration APIs directly, or abuse the connectivity‑test to perform SSRF. The high severity and remote nature of the vulnerability call for immediate remediation.
OpenCVE Enrichment