Posts
Vulnerability research, notes, and the occasional rant
02
A namespaced attacker creates a Kafka object and reads every Secret in every namespace, by making the Strimzi operator plant a Role and RoleBinding.
Kubernetes
CVE-2026-55225
22 July 2026
01
Any tenant with create GrafanaDashboard or GrafanaLibraryPanel access can read the Grafana operator's ServiceAccount token, which has effectively cluster-admin privilege. Grafana rated it Medium.
Kubernetes
CVE-2026-11769
18 July 2026