THREAT OPS › Threat News › [GHSA] GHSA-79gf-7frw-68m9 (critical) — Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system
[GHSA] GHSA-79gf-7frw-68m9 (critical) — Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system
GHSA-79gf-7frw-68m9 Severity: critical CVE: CVE-2026-54523
Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system
## Summary
In Kyverno v1.18.1, a tenant who can create a `NamespacedMutatingPolicy` in their own namespace can instruct the admission controller to generate resources
Indicators of compromise
- CVE-2026-54523cve
- namespacedmutatingpolicies.policies.kyverno.iodomain
- policies.kyverno.iodomain
Original source: https://github.com/advisories/GHSA-79gf-7frw-68m9