THREAT OPS › Threat News › [GHSA] GHSA-c8w2-fgvx-vhv4 (critical) — kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace
[GHSA] GHSA-c8w2-fgvx-vhv4 (critical) — kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace
GHSA-c8w2-fgvx-vhv4 Severity: critical CVE: CVE-2026-61682
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace
# Summary
The kcp front-proxy fails to strip client-supplied identity headers before forwarding requests to shards. Any authenticated tenant can inject their own
MITRE ATT&CK techniques
- External ProxyT1090.002
Indicators of compromise
- CVE-2026-61682cve
- authorization.kcp.iodomain
- authentication.kcp.iodomain
Original source: https://github.com/advisories/GHSA-c8w2-fgvx-vhv4