---
id: CVE-2026-84195
title: >-
  Kyverno before 1.16.4 automatically attaches the admission controller's
  ServiceAccount token to outbound HTTP requests in apiCall service mode without
  explicit authorization headers
summary: >-
  Kyverno before 1.16.4 automatically attaches the admission controller's
  ServiceAccount token to outbound HTTP requests in apiCall service mode without
  explicit authorization headers. Attackers can exfiltrate the token by
  directing apiCal…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-200
vendor: kyverno
product: github.com/kyverno/kyverno
affected:
  - github.com/kyverno/kyverno < 1.17.0
patched:
  - github.com/kyverno/kyverno 1.17.0
published: '2026-09-01'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:43:03.760'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84195'
references:
  - url: 'https://github.com/kyverno/kyverno/security/advisories/GHSA-8wfp-579w-6r25'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/kyverno-before-1.16.4-credential-leak-via-apicall
    label: disclosure@vulncheck.com
  - url: 'https://github.com/kyverno/kyverno/security/advisories/GHSA-8wfp-579w-6r25'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://github.com/kyverno/kyverno'
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-84195.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-84195'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-84195'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84195'
tags:
  - nvd
  - osv
  - go
  - csaf
  - vex
  - red-hat
epss: 0.00386
epssPercentile: 0.29902
aliases:
  - GHSA-8wfp-579w-6r25
  - GO-2026-5268
  - BIT-kyverno-2026-84195
ecosystem: go
ingestedAt: '2026-09-02T19:31:26.664Z'
---

## Overview

Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate the token by directing apiCall requests to external or attacker-controlled endpoints, gaining full control over Kyverno policies and cluster resources.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-84195)

Affected packages:

- `github.com/kyverno/kyverno < 1.17.0`

Patched in:

- `github.com/kyverno/kyverno 1.17.0`

Source: https://osv.dev/vulnerability/GHSA-8wfp-579w-6r25

## Vendor advisories

- **Red Hat VEX** · updated 2026-09-11 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-84195.json)
