OVERVIEW CVE-2026-39429 affects kcp, a Kubernetes-like control plane designed for workloads beyond traditional container environments. The vulnerability stems from the cache server being directly exposed on the root shard without any authentication or authorization mechanisms, allowing unauthenticated access to read and write operations. This flaw impacts all versions prior to 0.30.3 and 0.29.3, where patches have been released to remediate the issue. SEVERITY This vulnerability carries a critical CVSS score of 9.1, reflecting its high risk profile. The attack vector is network-based with low complexity, requiring no privileges or user interaction, making it easily exploitable by any actor with network access to the root shard. The impact includes both high confidentiality and integrity compromise, as attackers can read sensitive cached data and modify it, though availability is not directly affected. The FAUCET Risk Score of 53.0/100 indicates moderate-to-high contextual risk. EXPLOITATION STATUS There are currently no indications of active exploitation, as the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and appears inactive on threat intelligence hot lists. The EPSS score of 0.000780000 suggests minimal empirical exploit probability, though this should not diminish the urgency of patching given the critical severity rating and the trivial nature of the exploitation required. Organizations running affected kcp versions should prioritize immediate updates to the patched releases.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.29.3CPE matchmatch criteria | cpe:2.3:a:kcp:kcp:*:*:*:*:*:*:*:* | ||
>= 0.30.0, < 0.30.3CPE matchmatch criteria | cpe:2.3:a:kcp:kcp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.