[Report] Authentication Misconfiguration Fix

A misconfiguration was found in part of the authentication settings for PFCP’s Kubernetes clusters.

Under certain conditions, HTTP access through PFCP’s Identity-Aware Proxy could have allowed access to Pods in namespaces that the user was not authorized to access.

In response, the ExternalName Service feature used in the affected access path has been disabled, and the related authentication settings have been reviewed. This issue has been resolved.

Mitigation:

Completion Date:

May 12, 2026

User Impact:

No action is required from users. You can continue using the service as usual.


PFCP remains committed to maintaining and improving security so that users can use the service with confidence.