CVE-2026-23634
Pepr is a type safe K8s middleware. Prior to 1.0.5 , Pepr defaults to a cluster-admin RBAC configuration and does not explicitly force or enforce least-privilege guidance for module authors. The default behavior exists to make the “getting started” experience smooth: new users can experiment with Pepr and create resources dynamically without needing to pre-configure RBAC. This vulnerability is fixed in 1.0.5.
Scoring
- Severity
- NONE
- CVSS base score
- 0
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
- EPSS probability
- 0.24%
- CWE
- CWE-272
- Published
- 2026-01-16
- Last modified
- 2026-03-12
Affected products
- defenseunicorns pepr
Weakness type
Related vulnerabilities
- CVE-2026-79693 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79944 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2025-62299 — HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
- CVE-2026-59915 — Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege...
- CVE-2026-49500 — Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link...
- CVE-2026-15271 — TOTOLINK EX200 Web boa.conf least privilege violation
- CVE-2026-15270 — D-link DIR-823G Web boa.conf least privilege violation
- CVE-2026-11620 — TOTOLINK EX200 vsftpd vsftpd.conf least privilege violation