Overview

FieldValue
ID1006
NameCreate pods cluster-wide
Risk CategoryElevation of Privilege
Risk LevelCritical
Role TypeClusterRole
API Groupscore
Resourcespods
Verbscreate
TagsLateralMovement Persistence PrivilegeEscalation WorkloadExecution

Description

Allows creating new pods in any namespace across the cluster. This is highly critical as it can be used to deploy pods with elevated privileges (e.g., hostPath mounts, privileged security context), leading to node compromise, cluster-wide code execution, and establishing persistence.