{"id":"CVE-2026-61682","summary":"kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace","details":"kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* identity headers before forwarding requests to shards. Any authenticated tenant can inject X-Remote-Group: system:masters, authorization.kcp.io/warrant, authentication.kcp.io/scopes, or a group used for per-workspace required-group gating, and the shard trusts these values as authenticated identity assertions. This allows cross-workspace impersonation, authorization bypass, and arbitrary reading, writing, or deletion of resources, secrets, RBAC data, APIExports, APIBindings, and LogicalClusters. This issue is fixed in versions 0.31.4 and 0.32.2.","aliases":["GHSA-c8w2-fgvx-vhv4"],"modified":"2026-09-19T03:46:31.437609512Z","published":"2026-09-18T16:11:46.443Z","database_specific":{"cwe_ids":["CWE-290","CWE-302","CWE-348"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61682.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61682.json"},{"type":"FIX","url":"https://github.com/kcp-dev/kcp/commit/7437cdcfec8f927d1a9bf1b2dd1e075d038e27ca"},{"type":"FIX","url":"https://github.com/kcp-dev/kcp/commit/f913ee890fb2fd9fa78e50c43474b078bfb6aeff"},{"type":"WEB","url":"https://github.com/kcp-dev/kcp/releases/tag/v0.31.4"},{"type":"WEB","url":"https://github.com/kcp-dev/kcp/releases/tag/v0.32.2"},{"type":"ADVISORY","url":"https://github.com/kcp-dev/kcp/security/advisories/GHSA-c8w2-fgvx-vhv4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61682"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kcp-dev/kcp","events":[{"introduced":"0"},{"fixed":"7437cdcfec8f927d1a9bf1b2dd1e075d038e27ca"},{"introduced":"857068adc705066996fe9bbff21c0cb08382b5a6"},{"fixed":"f913ee890fb2fd9fa78e50c43474b078bfb6aeff"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"0.31.4"},{"introduced":"0.32.0"},{"fixed":"0.32.2"}]}}],"versions":["v0.31.3","v0.32.1","v0.32.0","v0.31.2","v0.31.1","v0.31.0","v0.29.0","v0.30.0","v0.29.0-rc.1","v0.29.0-rc.0","v0.28.0","sdk/v0.28.0","cli/v0.28.0","v0.27.0","sdk/v0.27.0","cli/v0.27.0","v0.27.0-rc.1","sdk/v0.27.0-rc.1","cli/v0.27.0-rc.1","v0.27.0-rc.0","sdk/v0.27.0-rc.0","cli/v0.27.0-rc.0","v0.26.0","sdk/v0.26.0","cli/v0.26.0","v0.26.0-rc1","sdk/v0.26.0-rc1","cli/v0.26.0-rc1","v0.25.0","sdk/v0.25.0","cli/v0.25.0","v0.24.0","sdk/v0.24.0","cli/v0.24.0","v0.23.0","sdk/v0.23.0","cli/v0.23.0","v0.22.0","sdk/v0.22.0","v0.21.0","sdk/v0.21.0","v0.20.0","sdk/v0.20.0","v0.11.0","pkg/apis/v0.11.0","v0.11.0-alpha.1","pkg/apis/v0.11.0-alpha.1","v0.10.0","pkg/apis/v0.10.0","v0.11.0-alpha.0","pkg/apis/v0.11.0-alpha.0","v0.9.0","pkg/apis/v0.9.0","v0.8.0","pkg/apis/v0.8.0","v0.7.0","pkg/apis/v0.7.0","v0.6.0-alpha.0","v0.5.0-alpha.1","pkg/apis/v0.5.0-alpha.1","v0.5.0-alpha.0","v0.4.0-alpha.0","v0.3.0-beta.1","v0.3.0-alpha.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-61682.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}