What is CVE-2026-14450?
CVE-2026-14450 is an authentication flaw in the MaaS API. This vulnerability allows any pod within the Kubernetes cluster to bypass the Kuadrant AuthPolicy gateway by forging trusted HTTP headers like `X-MaaS-Username` and `X-MaaS-Group`. Affected users should immediately update their MaaS API and enforce proper first-party authentication mechanisms.
Azərbaycanca: CVE-2026-14450 MaaS API-də tapılan autentifikasiya zəifliyidir. Bu boşluq Kubernetes klasterindəki istənilən pod-a `X-MaaS-Username` və `X-MaaS-Group` HTTP başlıqlarını saxtalaşdırmaqla Kuadrant AuthPolicy şlüzunu keçməyə imkan verir. Sistem administratorları dərhal təsirlənmiş MaaS API versiyalarını yeniləməli və autentifikasiya mexanizmlərini sərtləşdirməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
What can an attacker achieve by exploiting CVE-2026-14450 within a Kubernetes cluster?
An attacker can forge HTTP headers like `X-MaaS-Username` and `X-MaaS-Group` to bypass the Kuadrant AuthPolicy gateway and gain unauthorized access to the MaaS API.
What are the primary mitigation steps for CVE-2026-14450?
Affected MaaS API versions must be updated immediately, and proper first-party authentication mechanisms should be enforced.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.