PT-2026-77215 · Unknown · Managed-Serviceaccount

CVE-2026-75924

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions managed-serviceaccount (affected versions not specified)
Description A flaw exists where an addon-manager pod, granted excessive permissions via its ClusterRole, can be compromised to read any secret across all namespaces. Furthermore, the pod can approve arbitrary Certificate Signing Requests (CSRs), which are requests for a digital certificate to verify identity, potentially leading to information disclosure and privilege escalation within the cluster.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75924

Affected Products

Managed-Serviceaccount