Tag
high
advisory
Fleet PSS Bypass Vulnerability (CVE-2026-44938) via addLabelsFromOptions
A vulnerability in Fleet's agent-side deployer (CVE-2026-44938) allows an attacker with `git push` access to a Fleet-monitored repository to overwrite Pod Security Standards (PSS) enforcement labels on target Kubernetes namespaces, bypassing admission controls and enabling the deployment of otherwise prohibited workloads.
Fleet >= 0.15.0, < 0.15.2 +3
kubernetes
fleet
pss-bypass
admission-controller
supply-chain
defense-evasion
medium
advisory
Kubernetes Admission Controller Modification
2 rules 2 TTPsAn adversary modifies Kubernetes admission controller configurations to achieve persistence, escalate privileges, or gain unauthorized access to credentials within the cluster.
Kubernetes
admission-controller
privilege-escalation
persistence
credential-access
2r
2t
medium
advisory
Malicious Azure Kubernetes Admission Controller Configuration
2 rules 4 TTPsAn adversary can exploit Kubernetes Admission Controllers in Azure to achieve persistence, privilege escalation, or credential access by manipulating webhook configurations.
Azure Kubernetes Service +1
azure
kubernetes
admission-controller
persistence
privilege-escalation
credential-access
2r
4t