Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 01 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive exception takes precedence, allowing an attacker to bypass the policy by crafting a resource name that matches the second exception's name pattern (e.g., '*ingress*'). This can be used to circumvent policies such as one blocking hostPath volumes. Fixed in v1.13.0. | |
| Title | Kyverno before v1.13.0 Policy Bypass via Multiple Exceptions | |
| First Time appeared |
Kyverno
Kyverno kyverno |
|
| Weaknesses | CWE-284 | |
| CPEs | cpe:2.3:a:kyverno:kyverno:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kyverno
Kyverno kyverno |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-01T11:34:00.464Z
Reserved: 2026-09-01T11:03:27.972Z
Link: CVE-2026-84200
No data.
Status : Received
Published: 2026-09-01T12:17:49.540
Modified: 2026-09-01T12:17:49.540
Link: CVE-2026-84200
No data.
OpenCVE Enrichment
Updated: 2026-09-01T12:45:12Z