Database/Container, Kubernetes & orchestration
OpenShift Pipelines: every authenticated user gets write access to Kueue and cert-manager resources
Impact
The operator installs a ClusterRoleBinding that grants the system:authenticated group write access to Kueue and cert-manager custom resources. On a cluster where Kueue is the gating queue for GPU jobs, any authenticated user - including a tenant who only holds credentials for their own namespace - can delete other tenants' Workload objects, change scheduling priorities, or otherwise stall the queue, so accelerator capacity is held or handed to the wrong tenant with no exploit beyond a normal API call. The same binding lets a user drive cert-manager into overwriting TLS Secrets, including the default ingress controller certificate, which breaks or re-keys ingress for everything fronted by it. Nothing here requires a workload on a GPU node; it is an RBAC grant that ships with the operator, so it is present from install and stays until the binding is fixed.
Who can reach it
Any authenticated cluster user, from any namespace, reaching the Kubernetes API. No cluster-admin, no node access, and no GPU pod required. Only exploitable when Kueue or cert-manager CRDs are installed alongside OpenShift Pipelines.
What to do
Update the OpenShift Pipelines operator to a build that ships the corrected RBAC (Red Hat errata RHSA-2026:36648 and RHSA-2026:41036 cover the affected OpenShift Builds streams). The upgrade rolls the operator and its controller pods; running PipelineRuns are interrupted but no node drain or reboot is involved. Until the update lands, the exposure can be cut by deleting or narrowing tekton-scheduler-rolebinding so it no longer binds system:authenticated - verify Pipelines scheduling still works afterwards, and re-check the binding after any operator reconcile, since the operator may recreate it.
References
Related entries
- Nuclio Dashboard: unsanitized build tempDir yields command execution in a pod holding namespace-wide Secrets accessCVE-2026-79754 · Nuclio Dashboard (spec.build.tempDir, Kaniko container builder)High
- kube-compare: a container:// reference runs the untrusted image entrypoint instead of extracting from itCVE-2026-87114 · kube-compare (container:// reference path handling)High
- Consul Connect: unescaped service names generate over-broad Envoy RBAC rules, bypassing intentionsCVE-2026-88021 · HashiCorp Consul Connect service mesh (Envoy RBAC rule generation)High
- Harbor: fuzzy q filter on scanner credentials lets a project admin extract the adapter secret character by characterCVE-2026-92770 · Harbor registry (scanner registration AccessCredential, q query parameter)High
- BuildKit: build requesting a CDI device panics a daemon started with --cdi-disabledCVE-2026-93316 · BuildKit (CDI device handling when started with --cdi-disabled)High
- runc: Volume-mount race gives incorrect access control and privilege escalation to hostCVE-2019-19921 · runcHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.