Overview

FieldValue
ID1043
NameManage MutatingWebhookConfigurations
Risk CategoryTampering
Risk LevelCritical
Role TypeClusterRole
API Groupsadmissionregistration.k8s.io
Resourcesmutatingwebhookconfigurations
Verbscreate, update, patch, delete
TagsDenialOfService PrivilegeEscalation Tampering WebhookManipulation

Description

Grants control over MutatingWebhookConfigurations, which can modify API objects during admission. This is extremely critical as an attacker can create or alter webhooks to inject malicious configurations, escalate privileges, bypass security policies, or cause denial of service.