Kubetier
  1. Use the escalate verb to bypass privilege-escalation prevention

  2. Add */* rules to a ClusterRole already bound to you.

    Any write verb on the object does it, and no new binding is needed

  3. Permissions expand through the existing binding.

    Creating a fresh role and self-binding it instead requires bind clusterroles separately

Rights needed, any one set:

Note:

This is a by-design capability, not a CVE.

The escalate verb bypasses privilege-escalation prevention, so any identity holding it can grant permissions it does not already have.

No patch exists.

K8s docs ↗

Appears in 1 threat path