Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive exception takes precedence, allowing an attacker to bypass the policy by crafting a resource name that matches the second exception's name pattern (e.g., '*ingress*'). This can be used to circumvent policies such as one blocking hostPath volumes. Fixed in v1.13.0.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
Kyverno versions v1.9.0 through v1.12.7 contain a critical policy exception handling vulnerability that allows attackers to circumvent security policies through precedence exploitation. When enforce-mode policies are paired with multiple PolicyExceptions, the system incorrectly applies the less restrictive exception, enabling attackers to craft resource names matching permissive exception patterns (such as '*ingress*') to bypass controls like hostPath volume restrictions. This vulnerability is particularly dangerous in Kubernetes environments where Kyverno serves as a critical policy enforcement layer, affecting any organization using vulnerable versions to govern pod security, network policies, or storage access controls. The CVSS 9 severity reflects the high likelihood of exploitation and the immediate security impact—attackers can directly circumvent intended security policies without any additional privileges.
While MITRE ATT&CK mapping is not yet available for this vulnerability, practitioners using Casky.ai would detect attack patterns associated with Policy Bypass (T1562.008) and Defense Evasion techniques through behavioral analysis of resource creation attempts. Casky's extended reasoning capabilities, powered by Claude AI, would identify suspicious patterns such as: repeated creation attempts with incrementally modified resource names designed to match exception patterns; policy enforcement logs showing unexpected exception matches; and resource deployments that violate documented security policies but succeed. A practitioner reviewing Casky findings would observe anomalies in Kyverno audit logs indicating that restrictive policies (like blocking privileged containers or hostPath mounts) are being bypassed by resources with names or labels matching secondary PolicyExceptions—a pattern indicative of intentional policy circumvention rather than legitimate operational variance.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-84200. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation