logo

Kubernetes RBAC: How to Avoid Privilege Escalation

ID: e538f5bc-9844-5782-bcba-e99dc2b8615a

STIX ID: report--e538f5bc-9844-5782-bcba-e99dc2b8615a

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2022-04-06

Date Updated: 2026-04-26

...
...

This report describes how the Kubernetes CSR API can be abused for privilege escalation by creating and approving client certificates that impersonate high-privilege system accounts (for example system:kube-controller-manager), enabling attackers to read secrets and escalate to cluster-admin via service account tokens; it also recommends enabling Kubernetes auditing, restricting RBAC for CSR access, and using admission controllers to block risky signers or subjects.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.