CVE-2026-15140: Portworx Portworx Operator vulnerability
A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific conditions during the initial provisioning of a Portworx storage cluster, a user holding only limited, namespace-scoped permissions could cause the operator to grant broader access than intended, potentially resulting in elevated privileges within the Kubernetes cluster.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
The issue applies to Portworx Operator deployments on Red Hat OpenShift where a Portworx storage cluster is being initially provisioned. Exploitation requires a user who has limited namespace-scoped permissions.
When can the broader access be granted?
The condition occurs only under specific circumstances during initial provisioning of a Portworx storage cluster. The available information does not indicate that the issue applies after initial provisioning is complete.
What is the potential impact of exploitation?
A user with only namespace-scoped permissions could cause the operator to grant broader access than intended. This may allow elevated privileges within the Kubernetes cluster.