CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-62246

highCVSS 8.5covered by 1 sourcefirst seen 2026-07-30
Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and GetDefaultDatastoreUsername(), allowing distinct tenants with colliding normalized identifiers to share control-plane state and read, modify, or destroy another tenant's Kubernetes data. This issue is fixed in version 26.7.4-edge.

⚡ Watch CVE-2026-62246

Get an email if CVE-2026-62246 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-62246

CVE.org record

Embed the live status

CVE-2026-62246 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-62246 status](https://www.csirts.com/badge/CVE-2026-62246)](https://www.csirts.com/cve/CVE-2026-62246)