What is CVE-2026-16543?
CVE-2026-16543: A vulnerability in Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. The issue arises because the embedded KIC collects CA-certificate Secrets across all watched namespaces using a label selector. Immediate upgrade of Kong Operator to the latest patched version is strongly recommended.
Azərbaycanca: CVE-2026-16543: Kong Operator-un daxili Kong Kubernetes Ingress Controller (KIC) komponenti, namespace səviyyəsində Secret yaratmaq imkanı olan istifadəçiyə klaster miqyasında ingress konfiqurasiyası üzrə xidmət rəddi (DoS) yaratmağa imkan verir. Bu zəiflik KIC-in bütün nəzarət edilən namespace-lərdən CA-sertifikat Secret-lərini etiket seçicisi ilə toplaması nəticəsində yaranır. Bu problemə qarşı dərhal Kong Operator-u ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
What level of privileges does an attacker need to exploit CVE-2026-16543?
The attacker only needs namespace-scoped Secret creation privileges, but this allows them to cause a cluster-wide denial of service (DoS).
What is the root cause of CVE-2026-16543?
The vulnerability arises because the embedded KIC collects CA-certificate Secrets across all watched namespaces using a label selector.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.