Overview

FieldValue
ID1067
NameManage ServiceAccounts cluster-wide
Risk CategoryElevation of Privilege
Risk LevelHigh
Role TypeClusterRole
API Groupscore
Resourcesserviceaccounts
Verbscreate, update, patch, delete
TagsIdentityManagement PotentialPrivilegeEscalation Tampering

Description

Allows creating, updating, or deleting ServiceAccounts in any namespace. This can be used to create SAs, then bind them to privileged roles (if other RBAC permissions allow), or modify existing SAs, potentially interfering with workload identities.