Overview

FieldValue
ID1039
NameManage CronJobs cluster-wide (scheduled privileged execution, persistence)
Risk CategoryElevation of Privilege
Risk LevelCritical
Role TypeClusterRole
API Groupsbatch
Resourcescronjobs
Verbscreate, update, patch, delete
TagsPersistence PrivilegeEscalation Tampering WorkloadLifecycle

Description

Permits creating, updating, or deleting CronJobs across all namespaces. CronJobs schedule recurring batch jobs. This is critical as it allows scheduling the execution of pods (potentially privileged) at regular intervals, leading to privilege escalation, persistent access, and tampering.