Overview

FieldValue
ID1068
NameManage ServiceAccounts in a namespace
Risk CategoryElevation of Privilege
Risk LevelMedium
Role TypeRole
API Groupscore
Resourcesserviceaccounts
Verbscreate, update, patch, delete
TagsIdentityManagement PotentialPrivilegeEscalation Tampering

Description

Allows creating, updating, or deleting ServiceAccounts within a specific namespace. This can be used to create SAs within the namespace, which could then be bound to roles for privilege escalation within or from that namespace.