Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 01 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate the token by directing apiCall requests to external or attacker-controlled endpoints, gaining full control over Kyverno policies and cluster resources. | |
| Title | Kyverno before 1.16.4 Credential Leak via apiCall | |
| First Time appeared |
Kyverno
Kyverno kyverno |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:kyverno:kyverno:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kyverno
Kyverno kyverno |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-01T12:11:37.233Z
Reserved: 2026-09-01T10:51:59.729Z
Link: CVE-2026-84195
No data.
Status : Received
Published: 2026-09-01T12:17:49.130
Modified: 2026-09-01T12:17:49.130
Link: CVE-2026-84195
No data.
OpenCVE Enrichment
No data.