HIGH 8.3 NVD
CVE-2026-84195
Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit
Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate the token by directing apiCall requests to external or attacker-controlled endpoints, gaining full control over Kyverno policies and cluster resources.
References
- https://github.com/kyverno/kyverno/security/advisories/GHSA-8wfp-579w-6r25
- https://www.vulncheck.com/advisories/kyverno-before-1.16.4-credential-leak-via-apicall
- https://github.com/kyverno/kyverno/security/advisories/GHSA-8wfp-579w-6r25
This high severity vulnerability with a CVSS score of 8.3 was published on 2026-09-01 via NVD.
vulnfeed aggregates 11474 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.