CVE-2026-32768 Details
Description
Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. In versions prior to 0.6.5, due to a miswritten NetworkPolicy, a malicious actor can pivot from an instance to any Pod out of the origin namespace. This breaks the security-by-default property expected as part of the deployment program, leading to a potential lateral movement. In the specific case of sdk/kubernetes.Kompose it does not isolate the instances. This issue has been fixed in version 0.6.5.
A vulnerability in CTFER Chall-Manager versions prior to 0.6.5 allows malicious actors to pivot from one instance to any Pod in a different namespace. This issue arises from a misconfigured NetworkPolicy that fails to properly isolate instances, particularly in the 'sdk/kubernetes.Kompose' context. As a result, the expected security-by-default is compromised, potentially enabling lateral movement within the environment.
To address this vulnerability, update CTFER Chall-Manager to version 0.6.5 or later. If an immediate update is not possible, manually delete the 'inter-ns' NetworkPolicy in the affected namespace and apply the update as soon as feasible.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ctfer-io chall-manager | < 0.6.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 8, 2026 | Initial Analysis | [email protected] |
| Mar 20, 2026 | New CVE Received | [email protected] |