Impact
In KubePi versions up to and including 2.0.0, the cluster‑scoped APIs fail to validate per‑cluster access, allowing an authenticated user with cluster‑management permissions to read or modify data in clusters outside the set of clusters they are authorized to manage. This privilege escalation flaw enables unauthorized access to cluster data, which can lead to data leakage or unauthorized configuration changes.
Affected Systems
Affected product: KubePi by 1Panel‑dev. Vulnerable versions are 2.0.0 and earlier; the issue was resolved in version 2.0.1.
Risk and Exploitability
The CVSS base score is 5.8, indicating moderate severity, and EPSS is not available, but the flaw requires authenticated access and is not listed in the CISA KEV catalog. An attacker with valid cluster management credentials could exploit the missing per‑cluster checks to manipulate or read data in other clusters, especially if role assignments overlap. Upgrading to a fixed version mitigates the risk, but the absence of a high‑probability EPSS score suggests exploitation is possible but not likely in widespread attacks at this time.
OpenCVE Enrichment