Junglewise Threat Intelligence

CVE-2026-15140: Portworx Operator privilege escalation in OpenShift provisioning

CVE-2026-15140 · Severity: info · Published 2026-09-09

Executive brief

Portworx Operator is a Kubernetes application that manages persistent storage clusters on Red Hat OpenShift. During initial setup under specific conditions, a user with limited namespace-level permissions could trigger the operator to incorrectly grant broader cluster-wide access, allowing them to escalate their privileges and potentially compromise cluster security.

Technical details

This is a privilege-escalation vulnerability in the Portworx Operator's Kubernetes RBAC (Role-Based Access Control) handling. The vulnerability occurs specifically during the initial provisioning phase of a Portworx storage cluster, when the operator fails to properly validate or restrict permissions granted to namespace-scoped users. An attacker with limited namespace-scoped permissions can exploit this to cause the operator to grant unintended elevated cluster-wide access. The vulnerability requires specific conditions during cluster provisioning; patch availability has not been confirmed from the provided advisory text.

Affected products

  • Portworx Portworx Operator

Timeline

  • 2026-09-09: disclosed

References