NPM · SEPTEMBER 2026 · EARLY WARNING

Kyverno Policy Exception Handling Flaw: Critical CVE-2026-84200 Alert

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9
Affected component
kyverno (npm)
Affected versions
>= v1.13.0-rc.3, <= v1.13.0-rc.3 or >= kyverno-policies-chart-3.3.0-rc.3, <= kyverno-policies-chart-3.3.0-rc.3 or >= kyverno-chart-3.3.0-rc.3, <= kyverno-chart-3.3.0-rc.3 or >= v1.13.0-rc.2, <= v1.13.0-rc.2 or >= kyverno-policies-chart-3.3.0-rc.2, <= kyverno-policies-chart-3.3.0-rc.2 or >= kyverno-chart-3.3.0-rc.2, <= kyverno-chart-3.3.0-rc.2 or >= v1.13.0-rc.1, <= v1.13.0-rc.1 or >= kyverno-policies-chart-3.3.0-rc.1, <= kyverno-policies-chart-3.3.0-rc.1 or >= kyverno-chart-3.3.0-rc.1, <= kyverno-chart-3.3.0-rc.1 or >= v1.13.0-beta.1, <= v1.13.0-beta.1 or >= kyverno-policies-chart-3.3.0-beta.1, <= kyverno-policies-chart-3.3.0-beta.1 or >= kyverno-chart-3.3.0-beta.1, <= kyverno-chart-3.3.0-beta.1 or >= 1.9-dev, <= 1.9-dev or >= 1.8-dev, <= 1.8-dev or >= 1.7-dev, <= 1.7-dev or >= test-dev, <= test-dev or >= 1.6-dev, <= 1.6-dev or >= helm-chart-v2.1.3, <= helm-chart-v2.1.3 or >= v1.5.0-rc1, <= v1.5.0-rc1 or >= helm-chart-v2.1.0, <= helm-chart-v2.1.0 or >= v1.4.3, <= v1.4.3 or >= helm-chart-v2.0.3, <= helm-chart-v2.0.3 or >= v1.4.3-rc2, <= v1.4.3-rc2 or >= helm-chart-v2.0.3-rc2, <= helm-chart-v2.0.3-rc2 or >= v1.4.3-rc1, <= v1.4.3-rc1 or >= helm-chart-v2.0.3-rc1, <= helm-chart-v2.0.3-rc1 or >= v1.4.2, <= v1.4.2 or >= v1.4.2-rc4, <= v1.4.2-rc4 or >= v1.4.2-rc3, <= v1.4.2-rc3 or >= v1.4.2-rc2, <= v1.4.2-rc2 or >= v1.4.2-rc1, <= v1.4.2-rc1 or >= v1.4.1, <= v1.4.1 or >= v1.4.0-rc4, <= v1.4.0-rc4 or >= v1.4.0, <= v1.4.0 or >= v1.4.0-rc3, <= v1.4.0-rc3 or >= v1.4.0-rc2, <= v1.4.0-rc2 or >= v1.4.0-rc1, <= v1.4.0-rc1 or >= v1.3.6, <= v1.3.6 or >= v1.3.6-rc5, <= v1.3.6-rc5 or >= v1.3.6-rc4, <= v1.3.6-rc4 or >= v1.3.6-rc3, <= v1.3.6-rc3 or >= v1.3.6-rc2, <= v1.3.6-rc2 or >= v1.3.6-rc1, <= v1.3.6-rc1 or >= v1.3.5, <= v1.3.5 or >= v1.3.5-rc5, <= v1.3.5-rc5 or >= v1.3.5-rc4, <= v1.3.5-rc4 or >= v1.3.5-rc3, <= v1.3.5-rc3 or >= v1.3.5-rc2, <= v1.3.5-rc2 or >= v1.3.5-rc1, <= v1.3.5-rc1 or >= v1.3.4, <= v1.3.4 or >= v1.3.4-rc1, <= v1.3.4-rc1 or >= v1.3.3, <= v1.3.3 or >= v1.3.2, <= v1.3.2 or >= v1.3.2-rc3, <= v1.3.2-rc3 or >= v1.3.2-rc2, <= v1.3.2-rc2 or >= v1.3.2-rc1, <= v1.3.2-rc1 or >= v1.3.1, <= v1.3.1 or >= v1.3.0, <= v1.3.0 or >= v1.3.0-rc12, <= v1.3.0-rc12 or >= v1.3.0-rc11, <= v1.3.0-rc11 or >= v1.3.0-rc10, <= v1.3.0-rc10 or >= 1.3.0-rc10, <= 1.3.0-rc10 or >= v1.3.0-rc9, <= v1.3.0-rc9 or >= v1.3.0-rc8, <= v1.3.0-rc8 or >= v1.3.0-rc7, <= v1.3.0-rc7 or >= v1.3.0-rc6, <= v1.3.0-rc6 or >= v1.3.0-rc5, <= v1.3.0-rc5 or >= v1.3.0-rc4, <= v1.3.0-rc4 or >= v1.3.0-rc3, <= v1.3.0-rc3 or >= v1.3.0-rc2, <= v1.3.0-rc2 or >= v1.3.0-rc1, <= v1.3.0-rc1 or >= v1.2.1, <= v1.2.1 or >= v1.2.0, <= v1.2.0 or >= v1.1.12, <= v1.1.12 or >= v1.1.11, <= v1.1.11 or >= v1.1.10, <= v1.1.10 or >= v1.1.9, <= v1.1.9 or >= v1.1.8, <= v1.1.8 or >= v1.1.7, <= v1.1.7 or >= v1.1.7-rc4, <= v1.1.7-rc4 or >= v1.1.7-rc3, <= v1.1.7-rc3 or >= v1.1.7-rc2, <= v1.1.7-rc2 or >= v1.1.7-rc1, <= v1.1.7-rc1 or >= v1.1.6, <= v1.1.6 or >= v1.1.6-rc5, <= v1.1.6-rc5 or >= v1.1.6-rc4, <= v1.1.6-rc4 or >= v1.1.6-rc3, <= v1.1.6-rc3 or >= v1.1.6-rc2, <= v1.1.6-rc2 or >= v1.1.6-rc1, <= v1.1.6-rc1 or >= v1.1.5, <= v1.1.5 or >= v1.1.4, <= v1.1.4 or >= v1.1.4-rc1, <= v1.1.4-rc1 or >= v1.1.3, <= v1.1.3 or >= v1.1.3-rc1, <= v1.1.3-rc1 or >= v1.1.2, <= v1.1.2 or >= v1.1.1, <= v1.1.1 or >= v1.0.0, <= v1.0.0 or >= v1.0.0-rc1, <= v1.0.0-rc1 or >= v0.11.0, <= v0.11.0 or >= v0.10.0, <= v0.10.0 or >= v0.9.1, <= v0.9.1 or >= v0.9.0, <= v0.9.0 or >= v0.8.0, <= v0.8.0 or >= v0.7.1, <= v0.7.1 or >= v0.7.0, <= v0.7.0 or >= v0.5.0, <= v0.5.0 or >= v0.4.0, <= v0.4.0 or >= v0.3.0, <= v0.3.0 or >= v0.2.0, <= v0.2.0 or >= v0.1.0, <= v0.1.0
Patched version
v1.13.0
CVE-2026-84200

An early warning has been issued for a critical flaw in Kyverno versions v1.9.0 through v1.12.7 that allows policy bypass.

What happened

Kyverno versions v1.9.0 through v1.12.7 reportedly contain a policy exception handling flaw. This flaw allows an attacker to bypass policies by crafting a resource name. The vulnerability can be used to circumvent policies such as blocking hostPath volumes. The issue has been fixed in version v1.13.0.

The affected components include various Kyverno versions and related charts as specified in the threat data. Users of these versions are advised to upgrade to mitigate the risk.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If kyverno is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using Kyverno versions v1.9.0 through v1.12.7 or any of the specified related charts.

What should I do right now?

Upgrade to Kyverno v1.13.0 or later to mitigate the policy exception handling flaw.

Is there an official fix available?

Yes, the official fix is available in Kyverno v1.13.0.

Sources

Join the 0Day waitlist →

← Back to all threats