Executive brief
Portworx Operator is a Kubernetes application that manages persistent storage clusters on Red Hat OpenShift. During initial setup under specific conditions, a user with limited namespace-level permissions could trigger the operator to incorrectly grant broader cluster-wide access, allowing them to escalate their privileges and potentially compromise cluster security.
Technical details
This is a privilege-escalation vulnerability in the Portworx Operator's Kubernetes RBAC (Role-Based Access Control) handling. The vulnerability occurs specifically during the initial provisioning phase of a Portworx storage cluster, when the operator fails to properly validate or restrict permissions granted to namespace-scoped users. An attacker with limited namespace-scoped permissions can exploit this to cause the operator to grant unintended elevated cluster-wide access. The vulnerability requires specific conditions during cluster provisioning; patch availability has not been confirmed from the provided advisory text.
Affected products
- Portworx Portworx Operator
Timeline
- 2026-09-09: disclosed