A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:HKubernetes
APPKubernetes< 1.18.181.19.0 – 1.19.10 (excl.)1.20.0 – 1.20.6 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2026-13019CRITICAL9.8PL ✓same product
Esri Portal for ArcGIS – brak uwierzytelnienia dla krytycznej funkcji API
CVE-2026-33519CRITICAL9.8PL ✓same product
Nieprawidłowa autoryzacja w Esri Portal for ArcGIS — obejście uprawnień
CVE-2025-57870CRITICAL10.0PL ✓same product
SQL Injection w Esri ArcGIS Server — zdalny dostęp bez uwierzytelnienia
CVE-2018-1002105CRITICAL9.8PL ✓same product
Eskalacja uprawnień przez kube-apiserver w Kubernetes — nieautoryzowany dostęp do backendów
CVE-2017-1000056CRITICAL9.8PL ✓same product
Privilege escalation w Kubernetes PodSecurityPolicy admission plugin