Description
A flaw was found in the cluster-backup-operator. An attacker with write access to the backup storage location or the ability to create a Velero Backup object can inject malicious Role-Based Access Control (RBAC) resources into a backup. When this tampered backup is restored, the operator processes the malicious content, leading to a privilege escalation from backup-namespace-admin to hub cluster-admin. This allows the attacker to gain administrative control over the entire cluster.
Published: n/a
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The cluster-backup-operator contains a flaw that allows an attacker with write access to the backup storage location or who can create a Velero Backup object to inject malicious RBAC resources into a backup file. When a tampered backup is restored, the operator processes these resources, resulting in a privilege escalation from a backup-namespace-admin level to hub cluster-admin. This gives the attacker full administrative control over the cluster, compromising confidentiality, integrity and availability of all workloads.

Affected Systems

The vulnerability impacts the cluster-backup-operator component of Velero, which is commonly used in Kubernetes clusters to perform backups and restores. Any installation that uses this operator for Velero restores is potentially affected, especially when the backup storage location is accessible to untrusted writers or when arbitrary Velero Backup objects can be created.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity, and the vulnerability is not listed in the CISA KEV catalog. Because EPSS data is not available, the likelihood of exploitation cannot be quantified, but the attack vector is inferred to require the attacker to either write to the backup storage bucket or create a Velero Backup object. Once a malicious backup is introduced, the restore process automatically applies the injected RBAC resources, making exploitation straightforward for a knowledgeable attacker. The impact is system-wide privilege escalation, a critical risk for any cluster employing this operator.

Generated by OpenCVE AI on August 12, 2026 at 16:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch or upgrade for cluster-backup-operator that fixes this vulnerability
  • Restrict write permissions on the backup storage location so that only trusted users can modify or create backups
  • Configure Velero or the operator to filter or exclude cluster-scoped RBAC resources during restore operations

Generated by OpenCVE AI on August 12, 2026 at 16:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the cluster-backup-operator. An attacker with write access to the backup storage location or the ability to create a Velero Backup object can inject malicious Role-Based Access Control (RBAC) resources into a backup. When this tampered backup is restored, the operator processes the malicious content, leading to a privilege escalation from backup-namespace-admin to hub cluster-admin. This allows the attacker to gain administrative control over the entire cluster.
Title cluster-backup-operator: cluster-backup-operator: Velero Restore includes cluster-scoped RBAC resources with no exclusion — tampered backup yields hub cluster-admin
Weaknesses CWE-862
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}

threat_severity

Important


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-11T00:00:00Z

Links: CVE-2026-66797 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T16:15:03Z

Weaknesses