← Vulnerability feed

Vulnerability record · CVE-2022-45933 · published 27 November 2022

CVE-2022-45933: KubeView unauthenticated scrape endpoint exposes cluster admin certificates

KKubeview Project · Kubeview

KubeView through 0.1.31 exposes the api/scrape/kube-system endpoint without authentication, and that endpoint retrieves certificate files usable to authenticate as kube-admin. Because the exposed material is cluster-admin credentialing, any reachable instance effectively hands over control of the Kubernetes cluster. The vendor has stated the project was a side project and not intended to be secure, so no fix should be assumed from the vendor.

9.8 CVSS 3.1 Critical EPSS 52% · top 1.1% CWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin. NOTE: the vendor's position is that KubeView was a "fun side project and a learning exercise," and not "very secure."

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityUnauthenticated network access yields cluster-admin control of Kubernetes, with a 9.8 CVSS score and high EPSS despite no KEV listing.

What it is

KubeView through 0.1.31 exposes the api/scrape/kube-system endpoint without authentication, and that endpoint retrieves certificate files usable to authenticate as kube-admin. Because the exposed material is cluster-admin credentialing, any reachable instance effectively hands over control of the Kubernetes cluster. The vendor has stated the project was a side project and not intended to be secure, so no fix should be assumed from the vendor.

Impact

An unauthenticated attacker gains cluster-admin credentials and can take full control of the Kubernetes cluster, including reading secrets, modifying workloads and persisting access.

Attack surface

Reachable over the network via the KubeView HTTP service; the CVSS vector (AV:N/AC:L/PR:N/UI:N) and the missing-authentication CWE indicate no credentials and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.51696 (98.9th percentile) and both references are tagged Exploit, indicating public exploit material exists and exploitation is plausible.

What to do

  • Remove or isolate KubeView instances that cannot be upgraded; the vendor does not treat this as a supported secure product.
  • If KubeView must remain, place it behind an authenticating reverse proxy and restrict network access to trusted operators only.
  • Rotate any kube-admin or cluster-admin certificates and tokens that may have been exposed through the scrape endpoint.
  • Audit and restrict the service account and RBAC permissions granted to KubeView so it cannot read cluster-admin credential material.
  • Monitor for and block external access to the api/scrape/kube-system path at the ingress or WAF layer.

Detection

  • Search HTTP access logs for requests to api/scrape/kube-system, especially from unexpected or external source IPs.
  • Alert on Kubernetes API authentication using kube-admin or other cluster-admin certificates from unusual source addresses.
  • Monitor for creation of new cluster-admin role bindings, service accounts or tokens that could indicate post-exploitation persistence.
  • Inventory running KubeView instances and flag any version at or below 0.1.31 exposed beyond localhost.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/benc-uk/kubeview/issues/95 ExploitIssue TrackingThird Party Advisory
https://github.com/benc-uk/kubeview/issues/95 ExploitIssue TrackingThird Party Advisory

Track CVE-2022-45933 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-67277MikroTik RouterOS btest missing authentication leaks kernel memory and crashes kernelRouterOS accepts a "related" btest connection before the primary session is authenticated, letting an unauthenticated client start an IPv4 UDP test. …KEVEPSS 1.6%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed9.3CVE-2026-72529TrueConf Server missing authentication allows remote script executionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier expose an undocumented function on port 4307/TCP …KEVEPSS 1.5%analysed9.8CVE-2026-46817Oracle E-Business Suite Payments missing authentication allows takeoverOracle Payments in Oracle E-Business Suite 12.2.3 through 12.2.15 contains an easily exploitable flaw in the File Transmission component. An unauthen…KEVEPSS 0.81%analysed9.8CVE-2026-56164Microsoft SharePoint Server missing authentication allows privilege elevationMicrosoft Office SharePoint Server contains a missing authentication flaw in a critical function (CWE-306), letting an unauthenticated attacker reach…KEVEPSS 1.0%analysed9.8CVE-2026-20253Splunk Enterprise PostgreSQL sidecar missing authentication allows file writesSplunk Enterprise 10.2 below 10.2.4 and 10.x below 10.0.7 expose a PostgreSQL sidecar service endpoint that lacks authentication controls. Any networ…KEVEPSS 97%analysed9.8CVE-2026-35273Oracle PeopleSoft PeopleTools missing authentication allows takeoverOracle PeopleSoft Enterprise PeopleTools (Updates Environment Management component) in versions 8.61 and 8.62 is missing authentication for a critica…KEVEPSS 9.4%analysed9.3CVE-2026-41940cPanel and WHM login flow authentication bypasscPanel, WHM and WP Squared versions after 11.40 contain a missing-authentication flaw in the login flow (CWE-306) that lets unauthenticated remote at…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2022-45933), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.