logo

Privilege Escalation from Node/Proxy Rights in Kubernetes RBAC

ID: 443b4ee4-e1ec-5923-aeaa-1834c61d369f

STIX ID: report--443b4ee4-e1ec-5923-aeaa-1834c61d369f

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2022-03-03

Date Updated: 2026-04-26

...
...

This research post demonstrates that granting Kubernetes node/proxy RBAC rights can be abused to reach the Kubelet API (through the API server proxy or directly), enabling attackers with those rights to execute commands in pods as root and to bypass Kubernetes auditing and admission controls; the authors provide a PoC RBAC/ServiceAccount configuration and recommend restricting node/proxy permissions, firewalling Kubelet access, and monitoring for direct Kubelet usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.