CVE-2026-41323: Kyverno Default Sa Token Read
Reading the default Kubernetes ServiceAccount token ('/var/run/secrets/kubernetes.io/serviceaccount/token') directly from the filesystem. If this token is routed to an external or untrusted server, an attacker can intercept it and gain full privileges in the cluster. It is recommended to request an audience-scoped projected ServiceAccount token for external
greprules fetch cve-2026-41323-kyverno-default-sa-token-read --engine opengrepDescription
Reading the default Kubernetes ServiceAccount token ('/var/run/secrets/kubernetes.io/serviceaccount/token') directly from the filesystem. If this token is routed to an external or untrusted server, an attacker can intercept it and gain full privileges in the cluster. It is recommended to request an audience-scoped projected ServiceAccount token for external
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.