As cited
Copy frozen at (site build).
vulnerabilities
When “Read-Only” Isn’t: K8s nodes/proxy GET to RCE
A vulnerability in Kubernetes allows attackers with read-only access to nodes or proxy endpoints to achieve remote code execution across all pods on a node, potentially compromising entire clusters. Researchers from Horizon3 documented how a monitoring or observability agent granted read-only permissions can become a vector for escalating privileges and executing arbitrary code.
Why it matters: DevOps and platform teams running Kubernetes should audit monitoring agents and read-only service accounts immediately, as this path converts seemingly safe permissions into full cluster compromise.
- Source published
- First seen by Cybersecurity Tracker