chiprook
← Security
SecuritySeptember 23, 2026, 21:01

ConfigConfusion: one Kubernetes YAML grants GCP organization owner rights

Researcher Justin O'Leary disclosed ConfigConfusion: access to a namespace watched by Google Kubernetes Config Connector lets a user grant themselves any GCP role, including roles/owner on the whole organization, via an IAMPolicyMember resource. Google said KCC works as designed and the issue stems from administrator configuration.

ConfigConfusion: one Kubernetes YAML grants GCP organization owner rights
#Google#Kubernetes#GCP#KCC
Read next
Security

UAE and Saudi Arabia Absorb Half of Gulf Cyberattacks

Security

Hundreds of Leaked GitHub App Keys Still Authenticate

Security

FomoPeek crypto app in App Store hid iOS kernel exploits to steal wallet keys

Security

Attackers Poison ChatGPT, Gemini and Google AI Overview Answers