CVE-2026-44514
Kubetail is a real-time logging dashboard for Kubernetes. Prior to 0.14.0, Kubetail's dashboard exposes WebSocket endpoints that did not adequately validate the Origin header on connection upgrade. A malicious web page visited by a user with an active Kubetail session could open a WebSocket to the user's dashboard and read their Kubernetes logs in real time. This is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability and affects both the desktop deployment (default http://localhost:7500) and cluster deployments (typically behind an Ingress with HTTP basic auth). This vulnerability is fixed in 0.14.0.
Published:May 14, 2026
Last Modified:May 17, 2026
EPS:May 14, 2026
EPSS Score:0.00015
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Kubetail-org
Product
Cli
Kubetail-org
Cli
Vendor
Kubetail-org
Product
Dashboard
Kubetail-org
Dashboard
Vendor
Kubetail-org
Product
Kubetail
Kubetail-org
Kubetail
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
