Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-75924

Опубликовано: 18 авг. 2026
Источник: nvd
CVSS3: 8.7
EPSS Низкий

Описание

A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secret across all namespaces. Additionally, it can approve arbitrary Certificate Signing Requests (CSRs), which could lead to information disclosure and privilege escalation within the cluster.

EPSS

Процентиль: 5%
0.00159
Низкий

8.7 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 8.7
redhat
около 1 месяца назад

A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secret across all namespaces. Additionally, it can approve arbitrary Certificate Signing Requests (CSRs), which could lead to information disclosure and privilege escalation within the cluster.

CVSS3: 8.7
github
около 1 месяца назад

A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secret across all namespaces. Additionally, it can approve arbitrary Certificate Signing Requests (CSRs), which could lead to information disclosure and privilege escalation within the cluster.

EPSS

Процентиль: 5%
0.00159
Низкий

8.7 High

CVSS3

Дефекты

CWE-269