Manage ClusterRoles (create, update, patch, delete)
Elevation of Privilege
Critical
Overview
| Field | Value |
|---|---|
| ID | 1027 |
| Name | Manage ClusterRoles (create, update, patch, delete) |
| Risk Category | Elevation of Privilege |
| Risk Level | Critical |
| Role Type | ClusterRole |
| API Groups | rbac.authorization.k8s.io |
| Resources | clusterroles |
| Verbs | create, update, patch, delete |
| Tags | ClusterAdminAccess PrivilegeEscalation RBACManipulation |
Description
Allows creating, modifying, or deleting ClusterRoles. This grants the ability to define or alter cluster-wide permissions, enabling an attacker to grant themselves or others arbitrary privileges, including full cluster admin access, leading to complete cluster compromise.