Junglewise Threat Intelligence

CVE-2026-15584: Red Hat incluster-checks privilege escalation in debug pods

CVE-2026-15584 · Severity: high · CVSS 7.5 · Published 2026-07-13

Vendors: Red Hat.

Executive brief

A security flaw was found in a diagnostic tool used within OpenShift environments. The tool creates highly privileged temporary containers in a shared area where standard users typically have access. An attacker with basic developer-level permissions could hijack these containers to gain full administrative control (root access) over the underlying physical or virtual servers hosting the cluster, potentially leading to full data exposure or system takeover.

Technical details

The incluster-checks Python CLI tool (specifically in src/in_cluster_checks/core/executor.py) spawns privileged debug pods using 'oc debug node' to perform cluster health checks. These pods are configured with hostPID, hostNetwork, and a privileged securityContext, with the host root filesystem mounted at /host. By default, these pods are created in the 'default' namespace. Because the 'default' namespace often has broad RBAC permissions, any user with the standard 'edit' ClusterRole can use 'oc exec' to enter these pods. Once inside, the attacker can chroot into the host filesystem to obtain full root privileges on the cluster nodes. The vulnerability stems from a lack of namespace isolation and insufficient PodSecurity enforcement.

Affected products

  • Red Hat incluster-checks All versions prior to fix
  • Red Hat Pen Drive Powered by Red Hat Lightspeed 1

Timeline

  • 2026-07-13: disclosed: Vulnerability reported and published to NVD

References

Related threats