CVE-2026-29954 | KubePlus 4.1.4 webhook/kubeconfiggenerator ResourceComposition chartURL injection
A vulnerability was found in KubePlus 4.1.4 and classified as problematic. This issue affects the function ResourceComposition of the component webhook/kubeconfiggenerator. The manipulation of the argument chartURL results in injection.
This vulnerability is cataloged as CVE-2026-29954. The attack may be launched remotely. There is no exploit available.