THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-65956 — KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endpoints are exposed on the same public routing boundary as the SSO login and callback endpoints, so SSO, OIDC, and SAML management operations can be reached

[NVD] CVE-2026-65956 — KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endpoints are exposed on the same public routing boundary as the SSO login and callback endpoints, so SSO, OIDC, and SAML management operations can be reached

mednvdPublished 2026-08-26

CVE-2026-65956 CVSS: None Published: 2026-08-26T23:17:15.550

KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endpoints are exposed on the same public routing boundary as the SSO login and callback endpoints, so SSO, OIDC, and SAML management operations can be reached without administrator authorization. Because reading, cre

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-65956