CVE-2024-36532: Openkruise Kruise
Critical severity, CVSS 10.0. EPSS: 0.5% chance of exploitation in the next 30 days.
Insecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
Affected products
- Openkruise Kruise: version 1.6.2 only
Published 2024-06-21. Last modified 2026-06-17.