Skip to content

CVE-2026-100706 PoC, Exploit Status & Vulnerability Details TheHackerWire / 16h Real-time tracking of CVSS 9.0+ remote execution zero-days, public exploit code, and ransomware-linked vulnerabilities disclosed this week. Attack Vector How the vulnerability can be exploited Network

www.thehackerwire.com • September 27, 2026

kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. Attackers can exploit this by using percent-encoded directory traversal sequences to create MutatingWebhookConfiguration objects cluster-wide or PolicyException objects in the kyverno namespace, enabling privilege escalation to cluster admin.

Modify values to recalculate the CVSS score in real-time

References & External Links

CVE-2026-100706 AI (Artificial Intelligence) Analysis

CVE-2026-100706: Kyverno Path Traversal: Namespace Tenant to Cluster Admin Escalation

Community & Discussion

Critical Vulnerabilities — Last 7 Days

Real-time tracking of CVSS 9.0+ remote execution zero-days, public exploit code, and ransomware-linked vulnerabilities disclosed this week.

Frequently Asked Questions

CVE-2026-100706 is a Critical severity security vulnerability. kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects...

This vulnerability has a CVSS score of 9.9 out of 10, rated as Critical. Critical vulnerabilities can be exploited remotely without authentication and may lead to full system compromise, data theft, or malware installation.

To protect against CVE-2026-100706, you should: (1) Apply the latest security patches from the vendor, (2) Check official security advisories for specific remediation steps, (3) Update affected software to the latest version, and (4) Monitor your systems for any signs of exploitation.

This vulnerability was publicly disclosed on September 26, 2026. Organizations should check if they were vulnerable during the period before the patch was available.

No public exploit code has been confirmed for CVE-2026-100706 at this time. Security teams should monitor threat feeds for emerging developments and apply vendor patches proactively.

Currently, CVE-2026-100706 is not recorded in the CISA Known Exploited Vulnerabilities (KEV) catalog as being actively exploited in the wild. Security teams should still patch proactively to prevent zero-day targeting.

⚡ Security Analysis & Testing Tools

Extracted Entities