PT-2026-97041 · Gardener · Gardener

CVE-2026-79767

·

Published

2026-09-22

·

Updated

2026-10-01

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Gardener versions prior to 1.142.6 Gardener versions prior to 1.143.3 Gardener versions prior to 1.144.2 Gardener versions prior to 1.145.0
Description The customverbauthorizer admission plugin in the Gardener API server contains a flaw in its mustCheckProjectMembers() function. The plugin is intended to restrict the management of project members to users with the manage-members permission. However, the internal isHumanUser() function only identifies subjects of kind User, failing to account for Group or ServiceAccount subjects within Project.spec.members.
This allows a project administrator who lacks the manage-members permission to bypass the authorization check by adding arbitrary Group or ServiceAccount subjects. For example, adding the system:authenticated group can grant all authenticated users full project-level access, potentially exposing Shoots, Secrets, and cloud provider credentials.
Recommendations Update Gardener to version 1.142.6 or later. Update Gardener to version 1.143.3 or later. Update Gardener to version 1.144.2 or later. Update Gardener to version 1.145.0 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79767
GHSA-GFJV-GQF2-C888
GO-2026-6568

Affected Products

Gardener