Overview

FieldValue
ID1048
NameCreate ServiceAccount Tokens (ClusterRole for any SA in any namespace)
Risk CategorySpoofing
Risk LevelCritical
Role TypeClusterRole
API Groupsauthentication.k8s.io
Resourcesserviceaccounts/token
Verbscreate
TagsCredentialAccess Impersonation PrivilegeEscalation Spoofing TokenCreation

Description

Permits creating tokens for any ServiceAccount in any namespace. This is highly critical as it allows an attacker to generate tokens for highly privileged ServiceAccounts (e.g., those bound to cluster-admin), leading to impersonation, credential access, and full privilege escalation.