CVE-2026-65835
Last modified
CVE-2026-65835 is a medium-severity vulnerability rated 6.6/10 on the CVSS scale. Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResource RawItems and Generators in internal/controllers/resources/collect.go, including handleRawItem and handleGeneratorItem, did not apply the ResourceReference.LoadResources and IsNamespacedGVK cluster-scoped resource rejection guard used by NamespacedItems, allowing a Tenant Owner to create cluster-scoped resources such as ClusterRole or ValidatingWebhookConfiguration through the cluster-admin controller client. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResource RawItems and Generators in internal/controllers/resources/collect.go, including handleRawItem and handleGeneratorItem, did not apply the ResourceReference.LoadResources and IsNamespacedGVK cluster-scoped resource rejection guard used by NamespacedItems, allowing a Tenant Owner to create cluster-scoped resources such as ClusterRole or ValidatingWebhookConfiguration through the cluster-admin controller client. This issue is fixed in version 0.13.8.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| projectcapsule | capsule | >= 0.13.0, < 0.13.8 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-65835?
How severe is CVE-2026-65835?
How do I fix CVE-2026-65835?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-65814Heap-based buffer overflow in Windows Storage Port Driver al…7.8
- CVE-2026-65815Deserialization of untrusted data in Microsoft Dynamics 365 …8.8
- CVE-2026-65819gopacket provides packet processing capabilities for Go. Thr…7.5
- CVE-2026-6582A flaw has been found in TransformerOptimus SuperAGI up to 0…7.3
- CVE-2026-6583A vulnerability has been found in TransformerOptimus SuperAG…5.4
- CVE-2026-65834Capsule is a multi-tenancy and policy-based framework for Ku…6.8
- CVE-2026-6584A vulnerability was found in TransformerOptimus SuperAGI up …5.4
- CVE-2026-65841Jodit Editor is a WYSIWYG editor with a built-in file browse…5.3
- CVE-2026-6585A vulnerability was determined in TransformerOptimus SuperAG…5.4
- CVE-2026-6586A vulnerability was identified in TransformerOptimus SuperAG…6.3
- CVE-2026-6587A security flaw has been discovered in vibrantlabsai RAGAS u…6.3
- CVE-2026-65875BaserCMS provided by baserCMS Users Community contains a CSV…7.1
Are you affected by CVE-2026-65835?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
