VYPR
Critical severity9.1OSV Advisory· Published Jan 29, 2026· Updated Jun 17, 2026

CVE-2026-22806

CVE-2026-22806

Description

vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to versions 4.6.0, 4.5.4, 4.4.2, and 4.3.10, when an access key is created with a limited scope, the scope can be bypassed to access resources outside of it. However, the user still cannot access resources beyond what is accessible to the owner of the access key. Versions 4.6.0, 4.5.4, 4.4.2, and 4.3.10 fix the vulnerability. Some other mitigations are available. Users can limit exposure by reviewing access keys which are scoped and ensuring any users with access to them have appropriate permissions set. Creating automation users with very limited permissions and using access keys for these automation users can be used as a temporary workaround where upgrading is not immediately possible but scoped access keys are needed.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Loft Sh/LoftOSV2 versions
    v0.0.1-beta.1, v0.0.1-beta.10, v0.0.1-beta.11, …+ 1 more
    • (no CPE)range: v0.0.1-beta.1, v0.0.1-beta.10, v0.0.1-beta.11, …
    • (no CPE)range: <4.6.0, <4.5.4, <4.4.2, <4.3.10

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.