CVE-2026-26056 is a high-severity vulnerability affecting Yoke, a Helm-inspired infrastructure-as-code deployer, specifically versions 0.19.0 and earlier. It allows authenticated users with CR create/update permissions to inject a malicious URL via the overrides.yoke.cd/flight annotation, leading to arbitrary WebAssembly (WASM) code execution within the Air Traffic Controller (ATC) component. This enables attackers to create arbitrary Kubernetes resources or potentially escalate privileges to cluster-admin. The vulnerability has a CVSS score of 8.8 (High), indicating network exploitability with low privileges and no user interaction. Currently, there is no evidence of active exploitation or public exploit code, with minimal community discussion and media coverage, though a SUSE security update has been issued.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.19.0CPE matchmatch criteria | cpe:2.3:a:yokecd:yoke:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.