Kyverno vulnerability CVE-2026-54523: when the Kubernetes guard fails
INCIBE reports in advisory INCIBE-2026-588 the Kyverno vulnerability CVE-2026-54523, affecting versions 1.18.0 and 1.18.1. The component responsible for enforcing cluster policies also requires maintenance.

News summary
Advisory INCIBE-2026-588 documents vulnerability CVE-2026-54523 in Kyverno, specifically in versions 1.18.0 and 1.18.1. Kyverno is the engine that enforces policies in Kubernetes clusters: it determines which configurations are admitted and which are rejected.
The important nuance is the role played by the affected component. We are not looking at a business application, but at the control that prevents insecure configurations from being deployed. If that control can be bypassed, the guarantees the organisation took for granted are no longer sustained.
Our assessment is that these types of flaws reveal a common bias: what runs inside the cluster is monitored while what governs it is neglected. Admission controllers, operators, and security agents are part of the attack surface and require the same inventory and update cycle.
For companies running Kubernetes in production, the check is straightforward: which version of Kyverno is deployed in each cluster, including pre-production ones, and whether it corresponds to the affected versions. Upgrading to a patched version is the solution path.
As a reinforcement, it is advisable that critical policies do not rely on a single mechanism. Restricting permissions with RBAC, limiting who can deploy in sensitive namespaces, and reviewing changes to the policies themselves provides a second layer when the first one fails.
It is also worthwhile to log and alert on policy modifications. A silent change in an admission rule can go unnoticed for months and explain, at a later stage, how something that should not have reached production actually did.
Source: INCIBE — 27 August 2026
What happened
Advisory INCIBE-2026-588 documents vulnerability CVE-2026-54523 in Kyverno, in versions 1.18.0 and 1.18.1. Kyverno is the engine that enforces policies in Kubernetes clusters, deciding which configurations are admitted and which are rejected.
This isn't a business application but the control that prevents insecure configurations from being deployed: if that control can be bypassed, the guarantees the organisation took for granted no longer hold.
What it teaches a mid-sized business
This type of flaw reveals a common bias: what runs inside the cluster is monitored, while what governs it is neglected. Admission controllers, operators and security agents are part of the attack surface and need the same inventory and update cycle.
A silent change to an admission rule can go unnoticed for months and later explain how something that shouldn't have reached production got there.
What to review
Checks for companies running Kubernetes in production:
- Which Kyverno version is deployed in each cluster, including pre-production ones.
- Update to a fixed version if it matches the affected releases.
- Restrict permissions with RBAC and limit who can deploy into sensitive namespaces.
- Log and alert on any modification to admission policies.
Frequently Asked Questions
- Which Kyverno versions are affected by CVE-2026-54523?
- According to advisory INCIBE-2026-588, versions 1.18.0 and 1.18.1. Upgrading to a fixed version published by the project is recommended.
- Does an SME need admission policies in Kubernetes?
- If it runs Kubernetes in production, yes. They are the mechanism that prevents deployments with excessive privileges, unverified images or insecure configurations.
- What role does Kyverno play in a cluster?
- It acts as a policy engine: it decides which configurations are admitted into the Kubernetes cluster and which are rejected.
Concepts mentioned in this article: Vulnerability
If your container platform supports business services, its governance must be maintained and audited. At Seintec, we help you secure and operate your cloud and container environments. Contact us.
Contact SeintecRelated service
Cloud Services
Cloud services to scale your business.