Executive brief
Pinniped is a service used to manage authentication for Kubernetes clusters. A vulnerability in how it handles Active Directory groups could allow a user with specific administrative access to Active Directory to gain elevated permissions within a Kubernetes cluster. This risk is generally low as it requires the attacker to already have the ability to modify group names within the corporate directory service.
Technical details
A privilege escalation vulnerability exists in the Pinniped Supervisor's ActiveDirectoryIdentityProvider when the 'groupName' attribute is left empty. The flaw stems from improper parsing of Distinguished Names (DN) when determining Kubernetes group names, which can be manipulated via LDAP injection if an attacker can modify AD group entries (e.g., changing the Common Name). Exploitation requires the attacker to have high privileges (ability to edit AD group DNs), know a valid user's password, and for the Supervisor to be configured to include the edited group in search results. Successful exploitation allows the attacker to partially influence the group name seen by Kubernetes, potentially matching a group with higher privileges. The issue is fixed in version v0.47.0.
Affected products
- VMware Pinniped v0.11.0 through v0.46.0
Timeline
- 2026-07-08: advisory: GitHub advisory published by maintainers
- 2026-07-09: disclosed: NVD publication date
- 2026-07-09: patched: Fix released in version v0.47.0