CVE-2026-39429
Last modified
CVE-2026-39429 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by the root shard and has no authentication or authorization in place. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by the root shard and has no authentication or authorization in place. This allows anyone who can access the root shard to read and write to the cache server. This vulnerability is fixed in 0.30.3 and 0.29.3.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kcp | Kcp | < 0.29.3 |
| Kcp | Kcp | >= 0.30.0, < 0.30.3 |
References
- https://github.com/kcp-dev/kcp/releases/tag/v0.29.3Release Notes
- https://github.com/kcp-dev/kcp/releases/tag/v0.30.3Release Notes
- https://github.com/kcp-dev/kcp/security/advisories/GHSA-3j3q-wp9x-585pExploit, Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-39429?
How severe is CVE-2026-39429?
How do I fix CVE-2026-39429?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-39422MaxKB is an open-source AI assistant for enterprise. Version…5.4
- CVE-2026-39423MaxKB is an open-source AI assistant for enterprise. Version…5.4
- CVE-2026-39424MaxKB is an open-source AI assistant for enterprise. In vers…4.7
- CVE-2026-39425MaxKB is an open-source AI assistant for enterprise. Version…5.4
- CVE-2026-39426MaxKB is an open-source AI assistant for enterprise. Version…5.4
- CVE-2026-39428CubeCart is an ecommerce software solution. Prior to 6.6.0, …4.8
- CVE-2026-3943A vulnerability was found in H3C ACG1000-AK230 up to 2026022…7.3
- CVE-2026-39432Missing Authorization vulnerability in Arraytics Timetics al…8.2
- CVE-2026-39433Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 vers…6.5
- CVE-2026-39434Shop manager PHP Object Injection in CTX Feed <= 6.6.26 vers…7.2
- CVE-2026-39435Unauthenticated Cross Site Scripting (XSS) in CformsII <= 15…7.1
- CVE-2026-39436Cross-Site Request Forgery (CSRF) vulnerability in bgermann …7.1
Are you affected by CVE-2026-39429?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
