LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-75924

Published
CVSS8.7
Severityhigh
WeaknessCWE-269
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Description

A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secret across all namespaces. Additionally, it can approve arbitrary Certificate Signing Requests (CSRs), which could lead to information disclosure and privilege escalation within the cluster.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-75924

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-75924.