CVE-2026-32768
Severity CVSS v4.0:
HIGH
Type:
CWE-284
Improper Access Control
Publication date:
20/03/2026
Last modified:
08/04/2026
Description
Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. In versions prior to 0.6.5, due to a miswritten NetworkPolicy, a malicious actor can pivot from an instance to any Pod out of the origin namespace. This breaks the security-by-default property expected as part of the deployment program, leading to a potential lateral movement. In the specific case of sdk/kubernetes.Kompose it does not isolate the instances. This issue has been fixed in version 0.6.5.
Impact
Base Score 4.0
7.90
Severity 4.0
HIGH
Base Score 3.x
9.90
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ctfer-io:chall-manager:*:*:*:*:*:*:*:* | 0.6.5 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



