SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-15140

HIGH · CVSS 7.7 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A privilege escalation vulnerability exists in the Portworx Operator when deployed on Red Hat OpenShift, allowing users with limited, namespace-scoped permissions to gain broader access during the initial provisioning of a Portworx storage cluster. This could lead to unauthorized elevation of privileges within the Kubernetes environment, posing significant security risks. Organizations utilizing Kubernetes with Portworx on OpenShift should prioritize addressing this vulnerability to safeguard their cluster integrity.

CVE
CVE-2026-15140
Severity
HIGH
CVSS
7.7
EPSS
0.21%
Kubernetes

Original NVD Description

A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific conditions during the initial provisioning of a Portworx storage cluster, a user holding only limited, namespace-scoped permissions could cause the operator to grant broader access than intended, potentially resulting in elevated privileges within the Kubernetes cluster.