kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by the root shard and has no authentication or authorization in place. This allows anyone who can access the root shard to read and write to the cache server. This vulnerability is fixed in 0.30.3 and 0.29.3.
Metrics
Affected Vendors & Products
References
History
Thu, 09 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kcp-dev
Kcp-dev kcp |
|
| Vendors & Products |
Kcp-dev
Kcp-dev kcp |
Wed, 08 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by the root shard and has no authentication or authorization in place. This allows anyone who can access the root shard to read and write to the cache server. This vulnerability is fixed in 0.30.3 and 0.29.3. | |
| Title | kcp's cache server is accessible without authentication or authorization checks | |
| Weaknesses | CWE-302 CWE-862 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-08T20:16:04.015Z
Reserved: 2026-04-07T00:23:30.596Z
Link: CVE-2026-39429
No data.
Status : Awaiting Analysis
Published: 2026-04-08T21:16:59.313
Modified: 2026-04-08T21:26:13.410
Link: CVE-2026-39429
No data.