CVE-2026-26055 HIGH

CVE-2026-26055: Unauthenticated Admission Webhook Endpoints in Yoke ATC

Vendor Yokecd
Product yoke
Weakness CWE-306 · Missing auth
Published February 12, 2026
Last update February 12, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (ATC) component of Yoke. The ATC webhook endpoints lack proper authentication mechanisms, allowing any pod within the cluster network to directly send AdmissionReview requests to the webhook, bypassing Kubernetes API Server authentication. This enables attackers to trigger WASM module execution in the ATC controller context without proper authorization.

Key dates

02Disclosure timeline

February 12, 2026 CVE published
February 12, 2026 Record updated