THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jr6p-8pjj-mfx6 (medium) — Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)

[GHSA] GHSA-jr6p-8pjj-mfx6 (medium) — Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)

highgithub_advisoriesPublished 2026-07-31

GHSA-jr6p-8pjj-mfx6 Severity: medium CVE: CVE-2026-65835

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)

### Summary CVE-2026-22872 (GHSA-qjjm-7j9w-pw72) reported that a Tenant Owner could create cluster-scoped resources (e.g. `ClusterRole`, `ValidatingWebhookConfiguration`) t

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-jr6p-8pjj-mfx6