Description
A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific conditions during the initial provisioning of a Portworx storage cluster, a user holding only limited, namespace-scoped permissions could cause the operator to grant broader access than intended, potentially resulting in elevated privileges within the Kubernetes cluster.
Published: 2026-09-09
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a privilege‑escalation flaw in the Portworx Operator when it is deployed on Red Hat OpenShift. During the initial provisioning of a Portworx storage cluster, a user who holds only limited, namespace‑scoped permissions can manipulate the operator’s provisioning logic to grant broader access than intended. An attacker could therefore obtain elevated privileges within the Kubernetes cluster, potentially accessing or modifying resources beyond their assigned scope.

Affected Systems

This issue affects Everpure’s Portworx Operator running on Red Hat OpenShift (OCP). The flaw is only triggered under specific conditions during the first provisioning of a Portworx storage cluster. No particular operator or OpenShift version numbers are provided, so any deployment that uses the operator under these conditions is potentially vulnerable.

Risk and Exploitability

The CVSS score is 7.7, indicating a high severity level, while the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be local, as the escalation occurs during the operator’s initial provisioning process, which requires the attacker to have at least some namespace‑scoped access to the cluster. Because the flaw arises from the operator’s provisioning logic, a successful exploit would allow a malicious namespace user to gain cluster‑wide rights, compromising confidentiality, integrity, and availability of cluster resources.

Generated by OpenCVE AI on September 9, 2026 at 15:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest portworx operator patch or upgrade to a version that fixes the privilege escalation bug.
  • Restrict namespace‑scoped users from having permissions that trigger the provisioning workflow.
  • Implement stricter RBAC and audit logs to detect unauthorized escalations and ensure all cluster service accounts have least privilege.

Generated by OpenCVE AI on September 9, 2026 at 15:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Portworx Operator during OpenShift Provisioning

Wed, 09 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific conditions during the initial provisioning of a Portworx storage cluster, a user holding only limited, namespace-scoped permissions could cause the operator to grant broader access than intended, potentially resulting in elevated privileges within the Kubernetes cluster.
Weaknesses CWE-266
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Everpure

Published:

Updated: 2026-09-09T12:45:30.861Z

Reserved: 2026-07-08T17:17:55.388Z

Link: CVE-2026-15140

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-09T13:18:37.293

Modified: 2026-09-09T15:52:04.827

Link: CVE-2026-15140

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T16:00:17Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment