MEDIUMGo

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)

CVE-2026-65835Published 5 days agoUpdated 5 days agoSource: OSV

Affected packages

  • github.com/projectcapsule/capsule

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.19%
EPSS percentile
9.1%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 9%.

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) | HackTribune