Impact
A privilege escalation vulnerability has been discovered in the incluster‑checks tool used with OpenShift. The tool automatically creates privileged debug pods that mount the host file system into the shared default namespace. Any user with the standard edit role can exec into these pods, thereby gaining root permissions on the underlying cluster node. This flaw is an example of CWE‑250: Unnecessary Privilege.
Affected Systems
The affected product is the incluster‑checks component that ships with Red Hat’s Pen Drive Powered by Red Hat Lightspeed, currently at release version 1. It impacts OpenShift clusters that have the incluster‑checks tool enabled and expose the default namespace to users granted the edit role.
Risk and Exploitability
The CVSS score of 7.5 indicates a substantial impact, but the EPSS score of less than 1 % shows a very low global exploitation likelihood. Based on the description, it is inferred that the attack vector requires only standard edit rights on the default namespace, a common permission assignment, so the vulnerability can be leveraged within a compromised cluster. The vulnerability is not listed in the CISA KEV, yet the ability to reach node root makes it a serious risk for cluster administrators.
OpenCVE Enrichment