PT-2026-97041 · Gardener · Gardener
CVE-2026-79767
·
Published
2026-09-22
·
Updated
2026-10-01
CVSS v3.1
5.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Gardener versions prior to 1.142.6
Gardener versions prior to 1.143.3
Gardener versions prior to 1.144.2
Gardener versions prior to 1.145.0
Description
The
customverbauthorizer admission plugin in the Gardener API server contains a flaw in its mustCheckProjectMembers() function. The plugin is intended to restrict the management of project members to users with the manage-members permission. However, the internal isHumanUser() function only identifies subjects of kind User, failing to account for Group or ServiceAccount subjects within Project.spec.members.This allows a project administrator who lacks the
manage-members permission to bypass the authorization check by adding arbitrary Group or ServiceAccount subjects. For example, adding the system:authenticated group can grant all authenticated users full project-level access, potentially exposing Shoots, Secrets, and cloud provider credentials.Recommendations
Update Gardener to version 1.142.6 or later.
Update Gardener to version 1.143.3 or later.
Update Gardener to version 1.144.2 or later.
Update Gardener to version 1.145.0 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gardener