CVE-2026-32769 is a high-severity vulnerability (CVSS 7.1) affecting Fullchain versions prior to 0.1.1, caused by a misconfigured NetworkPolicy. This flaw allows a malicious actor to pivot from a compromised application to any Pod outside its original namespace, enabling lateral movement. The attack vector is network-based with low complexity, potentially leading to high impact on confidentiality, integrity, and availability across namespaces. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion, as indicated by its very low EPSS score. Organizations should upgrade to Fullchain version 0.1.1 or delete the problematic inter-ns- prefixed network policy as a workaround.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.1.1CPE matchmatch criteria | cpe:2.3:a:ctfer:fullchain:*:*:*:*:*:go:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.