CVE-2025-29922
CVSS 3.1 Score 9.6 of 10 (high)
Details
Summary
CVE-2025-29922 is a vulnerability affecting kcp, a Kubernetes-like control plane for various form-factors and use-cases. Before version 0.26.3, this issue allowed unauthorized creation and deletion of objects in any arbitrary target workspace via the APIExport VirtualWorkspace for pre-existing resources. This should only be possible when the workspace owner grants access to an API provider through an APIBinding. With this vulnerability, an attacker can bypass this requirement and manipulate objects regardless of the presence or status of an APIBinding. The vulnerability has been addressed in kcp versions 0.26.3 and 0.27.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- KCP