Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-65956

KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover and SSRF
Back to all
CVE

CVE-2026-65956

KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover and SSRF

KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endpoints are exposed on the same public routing boundary as the SSO login and callback endpoints, so SSO, OIDC, and SAML management operations can be reached without administrator authorization. Because reading, creating, and updating the global SSO configuration is not restricted to administrators, an unauthorized or low-privileged user can inspect or alter the authentication configuration, which under certain conditions can lead to account takeover or privilege escalation. The SSO connectivity-test function can additionally be abused as a server-side request forgery primitive, and the user list API returns user objects without consistently clearing authentication-related fields. This issue is fixed in version 2.0.0.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
10
-
4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
C
H
U
0
-
C
H
U
10
-
4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Related Resources

No items found.

References

https://github.com/1Panel-dev/KubePi/releases/tag/v2.0.0, https://github.com/1Panel-dev/KubePi/security/advisories/GHSA-wjrh-4j52-c664, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65956.json, https://nvd.nist.gov/vuln/detail/CVE-2026-65956, https://github.com/1Panel-dev/KubePi/commit/b62b41f82659e36102fccd215b13264b2035f1ea

Severity

0

CVSS Score
0
10

Basic Information

Base CVSS
0
EPSS Probability
0.00643%
EPSS Percentile
0.49216%
Introduced Version
0,v1.8.0,v1.7.1-0.20241230082710-77cf8a52c244
Fix Available
e026bf1e7f65b89257b22d3a229fb7f2b261eff5,2.0.0,v1.7.1-0.20260618093204-b62b41f82659

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading