THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-c8w2-fgvx-vhv4 (critical) — kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace

[GHSA] GHSA-c8w2-fgvx-vhv4 (critical) — kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace

highgithub_advisoriesPublished 2026-09-18

GHSA-c8w2-fgvx-vhv4 Severity: critical CVE: CVE-2026-61682

kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace

# Summary

The kcp front-proxy fails to strip client-supplied identity headers before forwarding requests to shards. Any authenticated tenant can inject their own

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-c8w2-fgvx-vhv4