← לוח פגיעויות

CVE-2026-42457

קריטית 9.0

תיאור (מקור, אנגלית)

vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0, there is a Stored XSS attack vulnerability via the name field of a templateRef. This can lead to the execution of arbitrary external scripts within the platform's browser context. In the worst case, a malicious user could potentially create a new Global-Admin user, bypassing other security restrictions. The attacker needs the ability to create namespaces. This vulnerability is fixed in 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0.

מדדים

CVSS 3.1
9.0 (CRITICAL) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
EPSS — סבירות ניצול
1% (אחוזון 000) נכון ל-30/9/2026
CWE
CWE-79

קישורים