Overview

FieldValue
ID1040
NameManage CronJobs in a namespace (scheduled privileged execution, persistence)
Risk CategoryElevation of Privilege
Risk LevelHigh
Role TypeRole
API Groupsbatch
Resourcescronjobs
Verbscreate, update, patch, delete
TagsPersistence PotentialPrivilegeEscalation Tampering WorkloadLifecycle

Description

Grants permission to create, update, or delete CronJobs within a specific namespace. This can be used to schedule the execution of potentially privileged pods, enabling privilege escalation, persistence, and tampering within that namespace.