As cited
Copy frozen at (site build).
vulnerabilities
[kubernetes] CVE-2026-2270: StatefulSet and ControllerRevision write permissions allow cross-namespace pod creation
A confused deputy attack in the Kubernetes StatefulSet controller allows a user with write access to StatefulSet and ControllerRevision resources within a namespace to instantiate pods in other namespaces. An attacker exploiting this vulnerability gains control over the target pod's configuration and namespace placement, though the cross-namespace pod is deleted immediately after creation.
Why it matters: Kubernetes cluster administrators and operators need to audit StatefulSet and ControllerRevision permissions across namespaces to prevent privilege escalation and lateral movement by users with limited write access.
- Source published
- First seen by Cybersecurity Tracker