CVE-2026-27112 is a critical vulnerability affecting Kargo versions from 1.7.0 up to, but not including, 1.7.8, 1.8.11, and 1.9.3. This flaw allows authenticated attackers to inject arbitrary resources into a project's namespace via specially crafted multi-document YAML payloads sent to Kargo's batch resource creation endpoints. With a CVSS score of 9.9 (CRITICAL), the vulnerability has a low attack complexity and can lead to privilege escalation, remote code execution, and secret exfiltration, leveraging the API server's permissions. There is currently no evidence of active exploitation, nor are public exploit codes like Metasploit or Nuclei available, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.7.0, < 1.7.8CPE matchmatch criteria | cpe:2.3:a:akuity:kargo:*:*:*:*:*:kubernetes:*:* | ||
>= 1.8.0, < 1.8.11CPE matchmatch criteria | cpe:2.3:a:akuity:kargo:*:*:*:*:*:kubernetes:*:* | ||
>= 1.9.0, < 1.9.3CPE matchmatch criteria | cpe:2.3:a:akuity:kargo:*:*:*:*:*:kubernetes:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.