High severity7.5OSV Advisory· Published Jan 3, 2019· Updated Jun 17, 2026
CVE-2018-18264
CVE-2018-18264
Description
Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: v0.1.0, v1.0.0, v1.0.0-beta1, …
Patches
Vulnerability mechanics
References
6- github.com/kubernetes/dashboard/pull/3289nvdPatchThird Party Advisory
- github.com/kubernetes/dashboard/pull/3400nvdPatchThird Party Advisory
- sysdig.com/blog/privilege-escalation-kubernetes-dashboard/nvdExploitThird Party Advisory
- www.securityfocus.com/bid/106493nvdThird Party AdvisoryVDB Entry
- github.com/kubernetes/dashboard/releases/tag/v1.10.1nvdRelease NotesThird Party Advisory
- groups.google.com/forum/nvd
News mentions
0No linked articles in our index yet.