HarborGuard / CVE
Back to search
CRITICALCVE-2026-42457Published Modified CNA GitHub_M

CVE-2026-42457: vCluster Platform: Stored XSS can lead to privilege escalation

vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0, there is a Stored XSS attack vulnerability via the name field of a templateRef. This can lead to the execution of arbitrary external scripts within the platform's browser context. In the worst case, a malicious user could potentially create a new Global-Admin user, bypassing other security restrictions. The attacker needs the ability to create namespaces. This vulnerability is fixed in 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0.

Metrics

CVSS v3.1
9.0
Severity
CRITICAL
Fixed in
Affected Products
1
Affected packages
  • loft-sh / loft
    < 4.4.3 · >=4.5.0-alpha.0 , < 4.5.5 · >= 4.6.0-alpha.1, < 4.6.2 · >= 4.7.0-alpha.0, < 4.7.1
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CVE-2026-42457: vCluster Platform: Stored XSS can lead to privilege escalation | HarborGuard CVE