Tag
Lighthouse Cross-Namespace Resource Injection Vulnerability
1 TTP 1 CVEA vulnerability in Submariner Lighthouse allows a compromised spoke cluster to inject unauthorized EndpointSlices and ServiceImports into peer cluster namespaces, leading to potential privilege escalation.
Red Hat Advanced Cluster Management Lighthouse Component DNS Hijacking
2 TTPs 1 CVEA vulnerability in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes allows a compromised spoke cluster to perform Man-in-the-Middle attacks via malicious EndpointSlice advertisements.
Privilege Escalation in HashiCorp Vault Secrets Operator
1 TTP 1 CVEA vulnerability in the HashiCorp Vault Secrets Operator allows a remote, authenticated attacker to escalate privileges, leading to potential unauthorized data disclosure or manipulation within Kubernetes environments.
CVE-2026-66782: Token Exposure in Submariner Operator
1 TTP 1 CVEThe Submariner operator exposes long-lived service account tokens within Custom Resource specifications, allowing attackers with RBAC access to gain full control over mesh network resources.
Broken Access Control in Rainbond API
1 rule 1 TTP 1 CVERainbond through version 6.9.7 contains an Insecure Direct Object Reference (IDOR) vulnerability (CVE-2026-72741) in the CheckToken function, allowing authenticated attackers to access or modify resources of other enterprise tenants.
Red Hat Multicluster Engine Confused Deputy Vulnerability
4 TTPs 1 CVEAn authenticated tenant can exploit CVE-2026-73266 in the Red Hat Multicluster Engine clusterclaims-controller to perform a cross-tenant cluster join, enabling the unauthorized injection of workloads and policies.
CVE-2026-18949: Privilege Escalation via Overly Permissive Service Account in Open Data Hub
2 TTPs 1 CVEA vulnerability in the Open Data Hub odh-dashboard allows an attacker with a compromised Service Account token to escalate to cluster-administrator privileges due to excessive RBAC permissions.
Improper Authorization in Data Science Pipelines (CVE-2026-18620)
1 TTP 1 CVEAn authorization bypass vulnerability in Data Science Pipelines allows restricted tenants to execute containers with elevated privileges by specifying a highly-privileged ServiceAccount in a CreateRun request.
Denial of Service Vulnerability in Red Hat Multicluster Engine for Kubernetes
2 TTPsA vulnerability in Red Hat Multicluster Engine for Kubernetes allows an unauthenticated remote attacker to trigger a denial of service condition by exploiting a software flaw.
Detection of Container Tunneling and Port Forwarding Tools
1 rule 2 TTPsElastic has released a detection rule for its Defend for Containers integration, identifying the use of tunneling and port forwarding tools within Linux containers, indicating potential threat actor activity such as command-and-control, data exfiltration, or lateral movement.
Potential Kubeletctl Execution Detected in Containers
1 rule 3 TTPsDetection engineers should be aware of the execution of `kubeletctl` within Linux containers, a tool attackers can leverage for discovery and lateral movement by interacting directly with the Kubelet API, potentially leading to unauthorized access and resource hijacking within a Kubernetes cluster.
Suspicious Process Execution in Containers from Transient Directories
1 rule 4 TTPsAdversaries exploit containerized environments by executing malicious code or interactive shells from transient, low-trust directories like /tmp or /dev/shm, or using executables with hidden names, to evade detection, establish persistence, and facilitate data exfiltration.
CRIU Restartable Sequences Vulnerability Allows Container Privilege Escalation
1 TTP 1 CVEA flaw, CVE-2026-18107, in CRIU's handling of restartable sequences (rseq) during checkpoint/restore allows a malicious process inside a container to hijack CRIU's parasite code injection, enabling the spoofing of process credentials in the checkpoint image and leading to elevated capabilities and zeroed UIDs/GIDs upon restore.
OS Command Injection in AWS CDK NodejsFunction Docker Bundling (CVE-2026-13760)
1 TTP 1 CVEAn OS command injection vulnerability, CVE-2026-13760, in AWS CDK's `aws-cdk-lib` package before version 2.260.0 allows an attacker to execute arbitrary commands on the host running the CDK toolchain by injecting shell metacharacters into dependency version strings within a project's `package.json` file when using Docker-based NodejsFunction bundling.
CVE-2026-15584 Privilege Escalation in OpenShift incluster-checks Tool
1 TTP 1 CVEA privilege escalation vulnerability, CVE-2026-15584, in Red Hat OpenShift's incluster-checks tool allows users with standard edit roles to obtain root access on cluster nodes by exploiting privileged debug pods with host filesystem access created in the shared default namespace.
Nuclio Controller Vulnerability Leads to Persistent Kubernetes RCE (GHSA-v5px-423j-pf7p)
2 rules 3 TTPs 2 IOCsThe Nuclio controller improperly sanitizes user-controlled input (cron trigger event headers and body) before injecting it into `curl` commands executed by Kubernetes CronJobs, allowing remote attackers to perform command injection and achieve remote code execution (RCE) by breaking quoting contexts in header keys or utilizing shell command substitution in event bodies, leading to arbitrary command execution with root privileges and potential persistence within the Kubernetes cluster.
Rancher Fleet Unauthenticated Webhook Regex Injection (CVE-2026-44937)
1 TTPAn unauthenticated regex injection vulnerability exists in Rancher Fleet's webhook endpoint when it's configured without a secret, allowing attackers to forge webhook requests using unsanitized repository URL components, which leads to continuous repository re-cloning, causing network and resource exhaustion (Denial of Service) on the management cluster, and potentially service downgrades if the attacker has read access to the target Git repository.
CVE-2026-50107: NGINX Gateway Fabric Configuration Injection Vulnerability
2 rules 1 TTP 5 CVEs 2 IOCsAn injection vulnerability, CVE-2026-50107, exists in the NGINX configuration generator component of NGINX Gateway Fabric when configured with NGINX Plus or NGINX Open Source as the data plane, allowing authenticated attackers with CRD modification permissions to inject arbitrary NGINX configuration directives via unsanitized user-supplied string values in the access log format setting, leading to control plane compromise and potential defense evasion or system impact.