Use the escalate verb to bypass privilege-escalation prevention
Add */* rules to a ClusterRole already bound to you.
Any write verb on the object does it, and no new binding is needed
Permissions expand through the existing binding.
Creating a fresh role and self-binding it instead requires bind clusterroles separately
Rights needed, any one set:
· escalate plus a way to write the rules
· editing an already-bound role needs no new binding
Note:
This is a by-design capability, not a CVE.
The escalate verb bypasses privilege-escalation prevention, so any identity holding it can grant permissions it does not already have.
No patch exists.

