CVE-2026-65956

10.0

1Panel-dev · KubePi

KubePi versions up to 1.6.15 allow unauthenticated users to access sensitive SSO configuration endpoints, leading to potential account takeover, privilege escalation, and server-side request forgery.

Executive summary

KubePi versions prior to 2.0.0 contain a critical authentication bypass vulnerability that permits unauthenticated attackers to gain full control over SSO configurations and sensitive user data.

Vulnerability

This flaw involves missing authentication for critical API endpoints, which allows unauthenticated actors to modify SSO, OIDC, and SAML settings, perform server-side request forgery, and retrieve sensitive user information.

Business impact

The ability for an unauthenticated attacker to manipulate authentication providers and extract user objects represents a total compromise of the management panel. Given the critical CVSS score of 10.0, this vulnerability poses an extreme risk of unauthorized administrative access, data theft, and the potential for lateral movement across the entire managed Kubernetes environment.

Remediation

Immediate Action: Update KubePi to version 2.0.0 or later immediately to resolve the authentication bypass flaw.

Proactive Monitoring: Review system and API access logs for anomalous requests to SSO configuration endpoints or unexpected calls to the user list API.

Compensating Controls: Implement strict network-level access controls to restrict access to the KubePi management interface to authorized IP ranges only until the update is applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability is of the highest severity and requires urgent attention from all security administrators. Because the flaw allows for unauthenticated modification of core security configurations, the only effective mitigation is to apply the provided patch in version 2.0.0 immediately. Failure to update leaves the Kubernetes management infrastructure exposed to full administrative compromise.

More 1Panel-dev CVEs

Sources