{"id":"CVE-2026-54523","summary":"Kyverno: NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system","details":"Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, allowing a namespace-scoped policy to invoke generator.apply(namespace, resources) with an arbitrary target namespace. The validation in pkg/cel/policies/mpol/validate.go checks that the policy compiles but does not enforce namespace scope, and GenerateResources in pkg/cel/libs/context.go does not reject the cross-namespace target. A user who can create NamespacedMutatingPolicy objects in one namespace can cause the admission controller, operating with cluster-wide privileges, to create ConfigMaps, NetworkPolicies, Secrets, RoleBindings, and other resources in another namespace, enabling unauthorized modification and potential privilege escalation. This issue is fixed in version 1.18.2.","aliases":["GHSA-79gf-7frw-68m9","GO-2026-6296"],"modified":"2026-08-28T11:47:27.873665044Z","published":"2026-08-26T14:20:37.236Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54523.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-862"]},"references":[{"type":"WEB","url":"https://github.com/kyverno/kyverno/releases/tag/v1.18.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54523.json"},{"type":"ADVISORY","url":"https://github.com/kyverno/kyverno/security/advisories/GHSA-79gf-7frw-68m9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54523"},{"type":"FIX","url":"https://github.com/kyverno/kyverno/commit/0919553c0ea1904f8d891280c92018da97946a06"},{"type":"FIX","url":"https://github.com/kyverno/kyverno/commit/5164bcdeda5b57678bc2d7a03ecc2cbb02982dae"},{"type":"FIX","url":"https://github.com/kyverno/kyverno/pull/16238"},{"type":"FIX","url":"https://github.com/kyverno/sdk/commit/6573937441443e1ba5af9fbb28d5c0f20297f9df"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kyverno/kyverno","events":[{"introduced":"78e7560a5531fda5a39ffb119d7d8e47527d8aee"},{"fixed":"0919553c0ea1904f8d891280c92018da97946a06"},{"fixed":"5164bcdeda5b57678bc2d7a03ecc2cbb02982dae"},{"fixed":"945ac9ce8546ea6cd51370f24b615148c577da5e"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"1.18.0"},{"fixed":"1.18.2"}]}},{"type":"GIT","repo":"https://github.com/kyverno/sdk","events":[{"introduced":"0"},{"fixed":"6573937441443e1ba5af9fbb28d5c0f20297f9df"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v1.18.2-rc.1","kyverno-policies-chart-3.8.2-rc.1","kyverno-chart-3.8.2-rc.1","v1.18.1","kyverno-policies-chart-3.8.1","kyverno-chart-3.8.1","v1.18.1-rc.2","kyverno-policies-chart-3.8.1-rc.2","kyverno-chart-3.8.1-rc.2","v1.18.1-rc.1","kyverno-policies-chart-3.8.1-rc.1","kyverno-chart-3.8.1-rc.1","v1.18.0","kyverno-policies-chart-3.8.0","kyverno-chart-3.8.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54523.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"}]}