Impact
The weakness occurs when the service‑ca‑operator’s ServiceAccount is bound to the cluster‑admin role, giving it unrestricted cluster‑wide permissions. This misconfiguration allows any actor that can interact with the operator or its workload to exercise complete control over the cluster, potentially creating, modifying, or deleting resources and compromising cluster integrity. The vulnerability is an example of improper authorization control, which is categorized as CWE‑250.
Affected Systems
Affected deployments include any Kubernetes cluster using the service‑ca‑operator component. No specific vendor, product version, or CPE details are provided, so any installation of the operator that retains the cluster‑admin binding is at risk.
Risk and Exploitability
The CVSS score of 9.0 indicates a critical severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector is that an adversary with the ability to influence or deploy code to the operator’s environment could leverage the cluster‑admin privileges to perform any action across the cluster, effectively bypassing standard authorization controls and enabling a full cluster takeover.
OpenCVE Enrichment