Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39429

33
FAUCET Score

OVERVIEW CVE-2026-39429 affects kcp, a Kubernetes-like control plane designed for workloads beyond traditional container environments. The vulnerability stems from the cache server being directly exposed on the root shard without any authentication or authorization mechanisms, allowing unauthenticated access to read and write operations. This flaw impacts all versions prior to 0.30.3 and 0.29.3, where patches have been released to remediate the issue. SEVERITY This vulnerability carries a critical CVSS score of 9.1, reflecting its high risk profile. The attack vector is network-based with low complexity, requiring no privileges or user interaction, making it easily exploitable by any actor with network access to the root shard. The impact includes both high confidentiality and integrity compromise, as attackers can read sensitive cached data and modify it, though availability is not directly affected. The FAUCET Risk Score of 53.0/100 indicates moderate-to-high contextual risk. EXPLOITATION STATUS There are currently no indications of active exploitation, as the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and appears inactive on threat intelligence hot lists. The EPSS score of 0.000780000 suggests minimal empirical exploit probability, though this should not diminish the urgency of patching given the critical severity rating and the trivial nature of the exploitation required. Organizations running affected kcp versions should prioritize immediate updates to the patched releases.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.29.3CPE matchmatch criteria
cpe:2.3:a:kcp:kcp:*:*:*:*:*:*:*:*
>= 0.30.0, < 0.30.3CPE matchmatch criteria
cpe:2.3:a:kcp:kcp:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
4.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.44%
Probability of exploitation in next 30 days
EPSS Percentile
35.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0044 is in the 13th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

gopatch availablevia ghsa
Product: github.com/kcp-dev/kcpFixed in: 0.30.3
gopatch availablevia ghsa
Product: github.com/kcp-dev/kcpFixed in: 0.29.3
github_advisoryworkaround availablevia nvd_reference
View patch

Vendor Advisories (1)

goGHSA-3j3q-wp9x-585phigh

kcp's cache server is accessible without authentication or authorization checks

Apr 8, 2026

References

github.com / kcp-dev/kcp/releases/tag/v0.29.3
Release Notes
github.com / kcp-dev/kcp/releases/tag/v0.30.3
Release Notes
github.com / kcp-dev/kcp/security/advisories/GHSA-3j3q-wp9x-585p
ExploitMitigationVendor Advisory