Vendor
The MaaS API incorrectly trusts X-MaaS-Username and X-MaaS-Group headers, allowing internal cluster pods to bypass authentication and escalate privileges to other tenants.