CVE-2026-79767
Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142.6, 1.143.3, 1.144.2, and 1.14
CVSS
5.5
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 22, 2026 · Last modified: Sep 22, 2026 · CWE-863
Not enough EPSS history yet.
Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142.6, 1.143.3, 1.144.2, and 1.145.0, the customverbauthorizer admission plugin's mustCheckProjectMembers manage-members check compares changes to User subjects but does not account for Group or ServiceAccount subjects in Project.spec.members. A project administrator who lacks manage-members permission can add arbitrary Group or ServiceAccount subjects, including the system:authenticated Group, and thereby grant broad project access. The resulting access can include Shoots, Secrets, and cloud provider credentials. This issue is fixed in versions 1.142.6, 1.143.3, 1.144.2, and 1.145.0.
- github.comhttps://github.com/gardener/gardener/commit/63751db97dca6cc5ee5f966d4963415de6ae5545
- github.comhttps://github.com/gardener/gardener/pull/15080
- github.comhttps://github.com/gardener/gardener/releases/tag/v1.144.2
- github.comhttps://github.com/gardener/gardener/security/advisories/GHSA-gfjv-gqf2-c888