Plan
active
Kubernetes Config Connector Allows GCP Org-Wide Privilege Escalation
- Engineer — Plan: GKE users running Config Connector should audit the service account’s IAM permissions and restrict who can submit YAML to affected clusters — a limited K8s principal could escalate to GCP org-level access via the connector’s delegated authority. No public PoC or active exploitation, but the attack path is now documented; tighten Config Connector RBAC and review org-level bindings this quarter.
- SOC/IR — Learn: A new confused-deputy escalation path from K8s YAML to GCP org control is worth adding to the analyst mental model for GKE environments, but there are no IOCs or active campaigns to hunt. File as a technique to watch if hunting lateral movement in GCP-connected clusters.
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.