Database/Control plane, storage & DevOps
Vault Secrets Operator: tenant-controlled AppRole config reads operator pod files and exfiltrates them
Impact
A tenant with only limited Kubernetes RBAC can point the operator's AppRole authentication configuration at an arbitrary path inside the operator pod and at an endpoint they control, causing the operator to read local files and transmit their contents outward. The Vault Secrets Operator pod holds the credentials that mint secrets for the whole cluster, so what leaks is not one namespace's data but the material used to fetch every namespace's. On a shared GPU cluster that is a direct path from a single tenant namespace to cluster-wide privilege escalation. Confidentiality and integrity are rated high with changed scope; availability is unaffected.
Who can reach it
A Kubernetes user or service account with limited RBAC in the cluster - enough to create or modify the operator's AppRole auth custom resource. Authentication to the cluster is required, but no cluster-admin rights.
What to do
Upgrade Vault Secrets Operator to 1.5.0 (affected: 1.3.0 through 1.4.1) and roll the operator deployment - a single pod restart, no node drain and no GPU workload impact. Because the flaw exfiltrates credentials rather than just reading them, rotate the Vault AppRole secret IDs and any tokens the operator pod held before deciding you are clear.
References
Related entries
- Johnson Controls Metasys Application and Data Server (ADS) deployed with SQL Express: Command injection on the MetasysCVE-2025-26385 · Johnson Controls Metasys Application and Data Server (ADS) deployed with SQL ExpressCritical
- CyberPower PowerPanel Business Local/Remote/Management v4.8.6 and earlier (Windows and Linux): A default passwordCVE-2023-25131 · CyberPower PowerPanel Business Local/Remote/Management v4.8.6 and earlier (Windows and Linux)Critical
- Grafana: Azure AD accounts validated on the mutable, non-unique email claimCVE-2023-3128 · GrafanaCritical
- Citrix NetScaler ADC/Gateway: "CitrixBleed" - memory overread leaking valid session tokensCVE-2023-4966 · Citrix NetScaler ADC/GatewayCritical
- GitLab: an unauthenticated GraphQL directive can modify or delete public projects and user dataCVE-2026-19478 · GitLab CE/EE (GraphQL API directive handling)Critical
- CloudNativePG: a database owner escalates to PostgreSQL superuser and OS command execution in the podCVE-2026-55769 · CloudNativePG instance manager (unpinned search_path on superuser connections)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.