SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-75924

HIGH · CVSS 8.7 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability exists in the managed-serviceaccount component, where a compromised addon-manager pod can exploit excessive permissions granted by its ClusterRole to access any secret across all namespaces and approve arbitrary Certificate Signing Requests (CSRs). This could lead to significant information disclosure and privilege escalation within the Kubernetes cluster. Organizations utilizing Kubernetes should prioritize addressing this issue to mitigate potential security breaches.

CVE
CVE-2026-75924
Severity
HIGH
CVSS
8.7
EPSS
0.16%

Original NVD Description

A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secret across all namespaces. Additionally, it can approve arbitrary Certificate Signing Requests (CSRs), which could lead to information disclosure and privilege escalation within the cluster.