Where
-Infinity
0

Hello Kubernetes Community,

A confused deputy attack exists in the StatefulSet controller that allows a user with namespace-scoped write permissions on StatefulSet and ControllerRevision objects to create a cross-namespace pod. An attacker exploiting this vulnerability would have full control over the resulting pod’s metadata and specification, including namespace selection. Note that the cross-namespace pod will be immediately deleted by the garbage collector unless the attacker is able to construct a valid StatefulSet OwnerReference. This would require referencing the UID of an existing StatefulSet in the victim’s namespace.

This issue has been rated Medium (5.9) CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N <https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N>, and assigned CVE-2026-2270.

Affected Versions

-

kube-controller-manager: <= v1.34.11 -

kube-controller-manager: <= v1.35.8 -

kube-controller-manager: <= v1.36.4 -

kube-controller-manager: = v1.37.0

How do I mitigate this vulnerability?

This issue can be mitigated by upgrading to a fixed kube-controller-manager version. The fixed versions are patched to ensure that only the spec field in StatefulSets will be restored from ControllerRevisions.

Fixed Versions

-

kube-controller-manager: >= v1.34.12 -

kube-controller-manager: >= v1.35.9 -

kube-controller-manager: >= v1.36.5 -

kube-controller-manager: >= v1.37.1

If you find evidence that this vulnerability has been exploited, please contact security () kubernetes io.

Additional Details

See the GitHub issue for more details: https://github.com/kubernetes/kubernetes/issues/142097

Acknowledgements

This vulnerability was reported by ImanOracle.

The issue was fixed and coordinated by:

Maciej Szulik @soltysh

Filip Křepinský @atiratree

Verónica López @Verolop

Jeremy Rickard @jeremyrickard

Nathan Herz @natherz97

Thank you,

Nathan Herz on behalf of the Kubernetes Security Response Committee

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203