Database/Container, Kubernetes & orchestration
KEDA: unvalidated service account token path in TriggerAuthentication reads any file from the KEDA pod
Impact
The path given in spec.hashiCorpVault.credential.serviceAccount is loaded without proper validation, so it can point anywhere in the KEDA operator pod's filesystem. The file contents are then sent to the Vault address configured in the same TriggerAuthentication, which the attacker also controls - the read turns straight into exfiltration to an external server. Anyone who can create or edit a TriggerAuthentication gets the KEDA pod's mounted secrets, its own ServiceAccount token, and any host paths the pod mounts. On a GPU cluster KEDA typically holds credentials for the queue or metrics backends that drive inference autoscaling, so this is a credential-theft path into the scaling control plane rather than into the GPUs themselves.
Who can reach it
Authenticated Kubernetes user with permission to create or modify TriggerAuthentication (or ClusterTriggerAuthentication) objects. Requires outbound network from the KEDA pod to the attacker's host.
What to do
Upgrade KEDA to 2.17.3 or 2.18.3 and roll the operator deployment - a pod restart of keda-operator, no node drain and no interruption to running workloads. Until then, restrict RBAC on TriggerAuthentication objects and audit existing ones for serviceAccount paths outside /var/run/secrets.
References
Related entries
- BuildKit: Insufficient validation of git URL fragment subdir allows access to files outside the intended checkoutCVE-2026-33748 · BuildKitHigh
- Kata Containers: Oversight in the CopyFile policy from v3.4.0 to v3.28.0CVE-2026-41326 · Kata ContainersHigh
- Open Cluster Management: forged client certificate lets a managed-cluster admin pivot to the hubCVE-2026-4740 · Open Cluster Management / Red Hat ACM multicluster engine (client certificate renewal)High
- containerd: CRI restores container.log from a checkpoint image without validating symlinksCVE-2026-53489 · containerdHigh
- Red Hat ACM submariner-operator: unvalidated image in the Submariner CR runs attacker code cluster-wideCVE-2026-66783 · Red Hat ACM submariner-operator (unvalidated image path in the Submariner CR)High
- Traefik: duplicate Ingress TLS option names drop mTLS client-certificate enforcementCVE-2026-85596 · Traefik Kubernetes Ingress NGINX provider (auth-tls-secret TLS options)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.