Kubernetes Cluster Management Vulnerability in Gardener by SAP
CVE-2026-79767
What is CVE-2026-79767?
The Gardener tool, which automates the management of Kubernetes clusters, contains a vulnerability in its custom verb authorizer admission plugin related to the manage-members permission. In versions prior to 1.142.6, 1.143.3, 1.144.2, and 1.145.0, the configuration fails to check Group or ServiceAccount subjects when comparing User subjects in Project.spec.members. This oversight enables a project administrator lacking manage-members permission to introduce arbitrary Group or ServiceAccount subjects, such as the system:authenticated Group, potentially granting unauthorized access to critical resources including Shoots, Secrets, and cloud provider credentials. Users are encouraged to upgrade to the latest versions to mitigate this risk.
Affected Version(s)
gardener < 1.142.6 < 1.142.6
gardener >= 1.143.0, < 1.143.3 < 1.143.0, 1.143.3
gardener >= 1.144.0, < 1.144.2 < 1.144.0, 1.144.2
