← Vulnerability feed

Vulnerability record · CVE-2023-22480 · published 14 January 2023

CVE-2023-22480: KubeOperator API improper authorization allows cluster takeover

Fit2cloud · Kubeoperator

KubeOperator versions 3.16.3 and below expose API interfaces to unauthorized entities, leaking sensitive information. The improper authorization can, under certain conditions, be used to take over the managed Kubernetes cluster. The issue is patched in version 3.16.4.

9.8 CVSS 3.1 Critical EPSS 67% · top 0.7% CWE-285 · Improper authorizationCWE-863 · Incorrect authorization
9.8CVSS 3.1 base score
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In KubeOperator versions 3.16.3 and below, API interfaces with unauthorized entities and can leak sensitive information. This vulnerability could be used to take over the cluster under certain conditions. This issue has been patched in version 3.16.4.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or interaction required and a very high EPSS score, plus potential full cluster takeover.

What it is

KubeOperator versions 3.16.3 and below expose API interfaces to unauthorized entities, leaking sensitive information. The improper authorization can, under certain conditions, be used to take over the managed Kubernetes cluster. The issue is patched in version 3.16.4.

Impact

An unauthenticated attacker can reach API endpoints and obtain sensitive information, and under certain conditions use that access to take over the cluster.

Attack surface

Reachable over the network via the KubeOperator API; the CVSS vector indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is high at 0.668 (99.3rd percentile), indicating elevated likelihood of exploitation; references are patch and advisory only, with no public exploit tag.

What to do

  • Upgrade KubeOperator to version 3.16.4 or later, which contains the patch.
  • Restrict network access to the KubeOperator API to trusted management networks only.
  • Audit API-facing deployments for unauthorized access and rotate any credentials or tokens that may have been exposed.
  • Review cluster-level permissions and service accounts for signs of unauthorized use.

Detection

  • Monitor KubeOperator API logs for requests to sensitive endpoints from unexpected or unauthenticated sources.
  • Alert on anomalous authentication failures or access patterns against the KubeOperator API.
  • Watch for unexpected changes to cluster configuration, RBAC or service accounts that could indicate takeover attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-22480 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2023-22480), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.