Tag
Remote Code Execution Vulnerability in SUSE NeuVector
1 TTPAn OS command injection vulnerability in the packet-capture filter component of SUSE NeuVector allows for unauthenticated remote code execution on affected Kubernetes nodes.
CVE-2026-100706: Path Traversal in Kyverno Policy apiCall Processing
2 TTPs 1 CVEKyverno versions before 1.19.1 contain a path traversal vulnerability in apiCall urlPath processing, enabling namespace-restricted users to perform unauthorized cluster-wide object manipulation via URL-encoded segments.
Unauthenticated Information Disclosure in OpenShift Console via CatalogdHandler
1 TTP 1 CVEA misconfiguration in the OpenShift Console CatalogdHandler allows unauthenticated remote attackers to leak internal operator-catalog data and relay requests into the catalogd namespace.
Command Injection Vulnerability in KubeEdge NodeUpgradeJob
1 TTP 1 CVEAn authenticated remote code execution vulnerability (CVE-2026-62371) in the KubeEdge v1alpha2 API allows attackers to inject shell commands via the NodeUpgradeJob resource.
Detection of Unauthorized Interactive Kubernetes API Probing
3 TTPsAdversaries performing hands-on-keyboard enumeration within compromised containers are detected by correlating interactive process execution with forbidden Kubernetes API audit responses.
Authentication Bypass in Trigger.dev via GitHub App Installation Binding
1 TTP 1 CVETrigger.dev versions before 4.6.0 contain an authentication bypass vulnerability allowing attackers to hijack GitHub App installations and gain unauthorized repository access by manipulating state cookies and installation identifiers.
Information Disclosure Vulnerability in multicluster-observability-addon
1 TTP 1 CVEA configuration reference vulnerability in the multicluster-observability-addon allows a managed cluster identity to bypass namespace restrictions and exfiltrate sensitive hub-level secrets.
Authentication Bypass in KubeEdge CloudCore Node Task Reporting
1 CVEKubeEdge CloudCore versions through 1.23.1 contain an authentication bypass vulnerability allowing unauthenticated remote attackers to manipulate node upgrade status reports via port 10002.
Unauthenticated Remote Access in argocd-mcp via CVE-2026-82456
2 TTPs 1 CVEThe argocd-mcp component version 0.8.0 insecurely binds its HTTP transport to all network interfaces and lacks authentication for MCP sessions when an API token is present, allowing remote attackers to perform unauthorized Argo CD resource modifications.
Unauthenticated Mutating Operations in Argo Rollouts Dashboard
1 TTP 1 CVEArgo Rollouts dashboard versions 1.10.0 and earlier expose sensitive, mutating operations without authentication, authorization, or CSRF protection when bound to all network interfaces.
Multiple Vulnerabilities in SUSE Rancher
2 TTPsSUSE Rancher contains multiple vulnerabilities that enable unauthenticated attackers to trigger denial of service, perform unauthorized information disclosure, and bypass security controls.
Lighthouse Cross-Namespace Resource Injection Vulnerability
1 TTP 1 CVEA vulnerability in Submariner Lighthouse allows a compromised spoke cluster to inject unauthorized EndpointSlices and ServiceImports into peer cluster namespaces, leading to potential privilege escalation.
Red Hat Advanced Cluster Management Lighthouse Component DNS Hijacking
2 TTPs 1 CVEA vulnerability in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes allows a compromised spoke cluster to perform Man-in-the-Middle attacks via malicious EndpointSlice advertisements.
Privilege Escalation in HashiCorp Vault Secrets Operator
1 TTP 1 CVEA vulnerability in the HashiCorp Vault Secrets Operator allows a remote, authenticated attacker to escalate privileges, leading to potential unauthorized data disclosure or manipulation within Kubernetes environments.
CVE-2026-66782: Token Exposure in Submariner Operator
1 TTP 1 CVEThe Submariner operator exposes long-lived service account tokens within Custom Resource specifications, allowing attackers with RBAC access to gain full control over mesh network resources.
Broken Access Control in Rainbond API
1 rule 1 TTP 1 CVERainbond through version 6.9.7 contains an Insecure Direct Object Reference (IDOR) vulnerability (CVE-2026-72741) in the CheckToken function, allowing authenticated attackers to access or modify resources of other enterprise tenants.
Red Hat Multicluster Engine Confused Deputy Vulnerability
4 TTPs 1 CVEAn authenticated tenant can exploit CVE-2026-73266 in the Red Hat Multicluster Engine clusterclaims-controller to perform a cross-tenant cluster join, enabling the unauthorized injection of workloads and policies.
CVE-2026-18949: Privilege Escalation via Overly Permissive Service Account in Open Data Hub
2 TTPs 1 CVEA vulnerability in the Open Data Hub odh-dashboard allows an attacker with a compromised Service Account token to escalate to cluster-administrator privileges due to excessive RBAC permissions.
Improper Authorization in Data Science Pipelines (CVE-2026-18620)
1 TTP 1 CVEAn authorization bypass vulnerability in Data Science Pipelines allows restricted tenants to execute containers with elevated privileges by specifying a highly-privileged ServiceAccount in a CreateRun request.
Denial of Service Vulnerability in Red Hat Multicluster Engine for Kubernetes
2 TTPsA vulnerability in Red Hat Multicluster Engine for Kubernetes allows an unauthenticated remote attacker to trigger a denial of service condition by exploiting a software flaw.
Detection of Container Tunneling and Port Forwarding Tools
1 rule 2 TTPsElastic has released a detection rule for its Defend for Containers integration, identifying the use of tunneling and port forwarding tools within Linux containers, indicating potential threat actor activity such as command-and-control, data exfiltration, or lateral movement.
Potential Kubeletctl Execution Detected in Containers
1 rule 3 TTPsDetection engineers should be aware of the execution of `kubeletctl` within Linux containers, a tool attackers can leverage for discovery and lateral movement by interacting directly with the Kubelet API, potentially leading to unauthorized access and resource hijacking within a Kubernetes cluster.
Suspicious Process Execution in Containers from Transient Directories
1 rule 4 TTPsAdversaries exploit containerized environments by executing malicious code or interactive shells from transient, low-trust directories like /tmp or /dev/shm, or using executables with hidden names, to evade detection, establish persistence, and facilitate data exfiltration.
CRIU Restartable Sequences Vulnerability Allows Container Privilege Escalation
1 TTP 1 CVEA flaw, CVE-2026-18107, in CRIU's handling of restartable sequences (rseq) during checkpoint/restore allows a malicious process inside a container to hijack CRIU's parasite code injection, enabling the spoofing of process credentials in the checkpoint image and leading to elevated capabilities and zeroed UIDs/GIDs upon restore.
OS Command Injection in AWS CDK NodejsFunction Docker Bundling (CVE-2026-13760)
1 TTP 1 CVEAn OS command injection vulnerability, CVE-2026-13760, in AWS CDK's `aws-cdk-lib` package before version 2.260.0 allows an attacker to execute arbitrary commands on the host running the CDK toolchain by injecting shell metacharacters into dependency version strings within a project's `package.json` file when using Docker-based NodejsFunction bundling.
CVE-2026-15584 Privilege Escalation in OpenShift incluster-checks Tool
1 TTP 1 CVEA privilege escalation vulnerability, CVE-2026-15584, in Red Hat OpenShift's incluster-checks tool allows users with standard edit roles to obtain root access on cluster nodes by exploiting privileged debug pods with host filesystem access created in the shared default namespace.
Nuclio Controller Vulnerability Leads to Persistent Kubernetes RCE (GHSA-v5px-423j-pf7p)
2 rules 3 TTPs 2 IOCsThe Nuclio controller improperly sanitizes user-controlled input (cron trigger event headers and body) before injecting it into `curl` commands executed by Kubernetes CronJobs, allowing remote attackers to perform command injection and achieve remote code execution (RCE) by breaking quoting contexts in header keys or utilizing shell command substitution in event bodies, leading to arbitrary command execution with root privileges and potential persistence within the Kubernetes cluster.
Rancher Fleet Unauthenticated Webhook Regex Injection (CVE-2026-44937)
1 TTPAn unauthenticated regex injection vulnerability exists in Rancher Fleet's webhook endpoint when it's configured without a secret, allowing attackers to forge webhook requests using unsanitized repository URL components, which leads to continuous repository re-cloning, causing network and resource exhaustion (Denial of Service) on the management cluster, and potentially service downgrades if the attacker has read access to the target Git repository.
CVE-2026-50107: NGINX Gateway Fabric Configuration Injection Vulnerability
2 rules 1 TTP 5 CVEs 2 IOCsAn injection vulnerability, CVE-2026-50107, exists in the NGINX configuration generator component of NGINX Gateway Fabric when configured with NGINX Plus or NGINX Open Source as the data plane, allowing authenticated attackers with CRD modification permissions to inject arbitrary NGINX configuration directives via unsanitized user-supplied string values in the access log format setting, leading to control plane compromise and potential defense evasion or system impact.