CVE-2026-53487: Kite-Org Kite

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated Kite users with any role can request `/api/v1/overview` for a cluster that their roles do not permit by selecting that cluster with `x-cluster-name`. The overview route is registered before `middleware.RBACMiddleware()` and `GetOverview` only checks `len(user.Roles) > 0`, so it returns aggregate Kubernetes inventory and capacity data from unauthorized clusters. Version 0.12.3 fixes the issue.

Affected products

  • Kite-Org Kite: before 0.12.3 (fixed in 0.12.3)

Published 2026-08-21. Last modified 2026-09-09.