Privilege Escalation Issue in Portworx Operator on Red Hat OpenShift
CVE-2026-15140
7.7HIGH
What is CVE-2026-15140?
A privilege escalation vulnerability exists in the Portworx Operator when utilized with Red Hat OpenShift. Under specific conditions during the initial setup of a Portworx storage cluster, users with limited, namespace-scoped permissions may inadvertently gain broader access rights. This could allow them to execute actions that are typically restricted, potentially compromising the security of the entire Kubernetes cluster.
Affected Version(s)
Portworx Operator 0 <= 26.3.1
Portworx Operator 26.3.2 +
