


Perceptive Security
SOC/SIEM Consultancy

Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit …
Published:
1 september 2026 om 00:00:00
Alert date:
1 september 2026 om 15:04:21
Source:
nvd.nist.gov
Cloud & Virtualization, Identity & Access, Data Breach & Exfiltration
Kyverno versions before 1.16.4 contain a critical vulnerability where the admission controller automatically attaches its ServiceAccount token to outbound HTTP requests when operating in apiCall service mode. This occurs without requiring explicit authorization headers, creating a significant security risk. Attackers can exploit this by directing apiCall requests to external or attacker-controlled endpoints to capture the token. Once obtained, the exfiltrated token grants full control over Kyverno policies and cluster resources. The vulnerability affects Kubernetes clusters using Kyverno as a policy engine. The fix is available in Kyverno version 1.16.4 and later. Users are advised to upgrade immediately to mitigate the risk of credential theft and cluster compromise.
Technical details
Mitigation steps:
Affected products:
Kyverno before 1.16.4
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-84195
https://github.com/kyverno/kyverno/security/advisories/GHSA-8wfp-579w-6r25
https://www.vulncheck.com/advisories/kyverno-before-1.16.4-credential-leak-via-apicall
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
