CVE-2026-62246
Received Received - Intake

Kamaji Tenant Data Isolation Bypass via Normalized Identifier Collision

Vulnerability report for CVE-2026-62246, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: GitHub, Inc.

Description

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and GetDefaultDatastoreUsername(), allowing distinct tenants with colliding normalized identifiers to share control-plane state and read, modify, or destroy another tenant's Kubernetes data. This issue is fixed in version 26.7.4-edge.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kamaji kamaji 26.7.4-edge

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-653 The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Kamaji is a Hosted Control Plane Manager for Kubernetes. This vulnerability exists in versions prior to 26.7.4-edge. It involves a flawed normalization process in functions GetDefaultDatastoreSchema() and GetDefaultDatastoreUsername() that derives datastore schema, database user, and etcd key prefix from tenant namespaces. This flaw allows distinct tenants with similar normalized identifiers to share control-plane state, potentially leading to unauthorized access and data manipulation across tenants.

Impact Analysis

If you use Kamaji for managing Kubernetes control planes, this vulnerability could allow an attacker to access, modify, or delete another tenant's Kubernetes data by exploiting colliding normalized identifiers. This could lead to data breaches, unauthorized changes, or service disruption within your Kubernetes environment.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating confidentiality and integrity requirements in GDPR and HIPAA. Non-compliance may result in legal penalties, reputational damage, and loss of trust due to potential data breaches or unauthorized exposure of sensitive information.

Mitigation Strategies

Upgrade Kamaji to version 26.7.4-edge or later to address the normalization issue in tenant control plane state management.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-62246. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart