What is CVE-2026-62246?
CVE-2026-62246 affects Kamaji, the Hosted Control Plane Manager for Kubernetes. Before version 26.7.4-edge, a flawed normalization in GetDefaultDatastoreSchema() and GetDefaultDatastoreUsername() could cause distinct TenantControlPlanes to share the same datastore schema, database user, and etcd key prefix. Upgrade to 26.7.4-edge immediately.
Azərbaycanca: CVE-2026-62246 Kamaji-nin Kubernetes üçün Hosted Control Plane Manager-də aşkarlanıb. 26.7.4-edge versiyasına qədər, GetDefaultDatastoreSchema() və GetDefaultDatastoreUsername() funksiyalarında namespace və adın səhv normallaşdırılması fərqli TenantControlPlane konfiqurasiyaları üçün eyni datastore sxemi, verilənlər bazası istifadəçisi və etcd açar prefiksinin yaranmasına səbəb olur. Dərhal 26.7.4-edge versiyasına yeniləmə tövsiyə olunur.
FAQ2
Which versions of Kamaji are affected by CVE-2026-62246?
This vulnerability affects versions of Kamaji prior to 26.7.4-edge.
How can I mitigate CVE-2026-62246?
You should immediately upgrade Kamaji to version 26.7.4-edge.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.