{"id":"CVE-2026-79767","published":"2026-09-22T20:17:08.957","lastModified":"2026-09-23T18:12:04.247","description":"Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142.6, 1.143.3, 1.144.2, and 1.145.0, the customverbauthorizer admission plugin's mustCheckProjectMembers manage-members check compares changes to User subjects but does not account for Group or ServiceAccount subjects in Project.spec.members. A project administrator who lacks manage-members permission can add arbitrary Group or ServiceAccount subjects, including the system:authenticated Group, and thereby grant broad project access. The resulting access can include Shoots, Secrets, and cloud provider credentials. This issue is fixed in versions 1.142.6, 1.143.3, 1.144.2, and 1.145.0.","cvssScore":5.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N","cwes":["CWE-863"],"vendors":[],"products":[],"references":[{"url":"https://github.com/gardener/gardener/commit/63751db97dca6cc5ee5f966d4963415de6ae5545","tags":[]},{"url":"https://github.com/gardener/gardener/pull/15080","tags":[]},{"url":"https://github.com/gardener/gardener/releases/tag/v1.144.2","tags":[]},{"url":"https://github.com/gardener/gardener/security/advisories/GHSA-gfjv-gqf2-c888","tags":[]}],"exploitRefs":[{"url":"https://github.com/gardener/gardener/commit/63751db97dca6cc5ee5f966d4963415de6ae5545","tags":[]},{"url":"https://github.com/gardener/gardener/pull/15080","tags":[]},{"url":"https://github.com/gardener/gardener/releases/tag/v1.144.2","tags":[]},{"url":"https://github.com/gardener/gardener/security/advisories/GHSA-gfjv-gqf2-c888","tags":[]}],"hasPoc":true,"ai":null}