Overview

FieldValue
ID1061
NameWildcard permission on all resources in a namespace (Namespace Admin)
Risk CategoryElevation of Privilege
Risk LevelCritical
Role TypeRole
API Groups*
Resources*
Verbs*
TagsDenialOfService InformationDisclosure NamespaceAdmin PotentialPrivilegeEscalation Spoofing (+2 more)

Description

Grants unrestricted, wildcard (’*’) access to all API groups, resources, and verbs within a specific namespace. This provides full administrative control over that namespace and can often be leveraged to escalate privileges to cluster-wide admin depending on the cluster configuration and installed operators.