CYBERSECURITYTRACKER
TRACKING7,595 stories in this site build1,630 vulnerability news stories in this site build
Permanent story citation

[kubernetes] CVE-2026-2270: StatefulSet and ControllerRevision write permissions allow cross-namespace pod creation

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8380

As cited

Copy frozen at (site build).

vulnerabilities

[kubernetes] CVE-2026-2270: StatefulSet and ControllerRevision write permissions allow cross-namespace pod creation

A confused deputy attack in the Kubernetes StatefulSet controller allows a user with write access to StatefulSet and ControllerRevision resources within a namespace to instantiate pods in other namespaces. An attacker exploiting this vulnerability gains control over the target pod's configuration and namespace placement, though the cross-namespace pod is deleted immediately after creation.

Why it matters: Kubernetes cluster administrators and operators need to audit StatefulSet and ControllerRevision permissions across namespaces to prevent privilege escalation and lateral movement by users with limited write access.

VendorsKubernetes
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary