Manage CronJobs cluster-wide (scheduled privileged execution, persistence)
Elevation of Privilege
Critical
Overview
| Field | Value |
|---|---|
| ID | 1039 |
| Name | Manage CronJobs cluster-wide (scheduled privileged execution, persistence) |
| Risk Category | Elevation of Privilege |
| Risk Level | Critical |
| Role Type | ClusterRole |
| API Groups | batch |
| Resources | cronjobs |
| Verbs | create, update, patch, delete |
| Tags | Persistence PrivilegeEscalation Tampering WorkloadLifecycle |
Description
Permits creating, updating, or deleting CronJobs across all namespaces. CronJobs schedule recurring batch jobs. This is critical as it allows scheduling the execution of pods (potentially privileged) at regular intervals, leading to privilege escalation, persistent access, and tampering.