CVE-2026-62246CWE-284CWE-653broken-access-control

CVE-2026-62246

High · published July 31, 2026

CVSS v3.1
8.5
EPSS
0%
Percentile
18.9
In the wild
Unconfirmed
What it is

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and GetDefaultDatastoreUsername(), allowing distinct tenants with colliding normalized identifiers to share control-plane state and read, modify, or destroy another tenant's Kubernetes data. This issue is fixed in version 26.7.4-edge.

The record
Technical detail
CVSS v3.1
8.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00269 · 18.9th percentile
Weaknesses
CWE-284 · Improper Access Control; CWE-653 · Improper Isolation or Compartmentalization
Published
2026-07-31T02:16Z
References (3)
EPSS history
Timeline
  • 30 JUL 21:06Z
    Kamaji: TenantControlPlane namespace/name collision binds two tenants to the same SQL datastore schema + DB user, breaking per-tenant isolation
    cvelistv5