Kubernetes Cluster Management Vulnerability in Gardener by SAP
CVE-2026-79767

5.5MEDIUM

Key Information:

Vendor

Gardener

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-79767?

The Gardener tool, which automates the management of Kubernetes clusters, contains a vulnerability in its custom verb authorizer admission plugin related to the manage-members permission. In versions prior to 1.142.6, 1.143.3, 1.144.2, and 1.145.0, the configuration fails to check Group or ServiceAccount subjects when comparing User subjects in Project.spec.members. This oversight enables a project administrator lacking manage-members permission to introduce arbitrary Group or ServiceAccount subjects, such as the system:authenticated Group, potentially granting unauthorized access to critical resources including Shoots, Secrets, and cloud provider credentials. Users are encouraged to upgrade to the latest versions to mitigate this risk.

Affected Version(s)

gardener < 1.142.6 < 1.142.6

gardener >= 1.143.0, < 1.143.3 < 1.143.0, 1.143.3

gardener >= 1.144.0, < 1.144.2 < 1.144.0, 1.144.2

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.