Vulnerability Description
Pepr is a type safe K8s middleware. Prior to 1.0.5 , Pepr defaults to a cluster-admin RBAC configuration and does not explicitly force or enforce least-privilege guidance for module authors. The default behavior exists to make the “getting started” experience smooth: new users can experiment with Pepr and create resources dynamically without needing to pre-configure RBAC. This vulnerability is fixed in 1.0.5.
CVSS Score
NONE
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Defenseunicorns | Pepr | < 1.0.5 |
Related Weaknesses (CWE)
References
- https://github.com/defenseunicorns/pepr/releases/tag/v1.0.5Release Notes
- https://github.com/defenseunicorns/pepr/security/advisories/GHSA-w54x-r83c-x79qVendor Advisory
FAQ
What is CVE-2026-23634?
CVE-2026-23634 is a vulnerability with a CVSS score of 0.0 (NONE). Pepr is a type safe K8s middleware. Prior to 1.0.5 , Pepr defaults to a cluster-admin RBAC configuration and does not explicitly force or enforce least-privilege guidance for module authors. The defau...
How severe is CVE-2026-23634?
CVE-2026-23634 has been rated NONE with a CVSS base score of 0.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-23634?
Check the references section above for vendor advisories and patch information. Affected products include: Defenseunicorns Pepr.