ZeroHour

CVE-2026-15140

moderate

Privilege Escalation in Portworx Operator on Red Hat OpenShift

CVSS 4.0
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-15140 is an incorrect privilege assignment flaw (CWE-266) in the Portworx Operator when it is deployed on Red Hat OpenShift. It can be triggered only under specific conditions during the initial provisioning of a Portworx storage cluster, when a user holding only limited, namespace-scoped permissions causes the operator to grant broader access than intended. An attacker who is able to trigger the flaw gains elevated privileges within the Kubernetes/OpenShift cluster, beyond the namespace-scoped access they legitimately hold. Only organizations running the Portworx Operator on OpenShift are affected, and only during that narrow provisioning window. The flaw is not in CISA's Known Exploited Vulnerabilities catalog, no public proof-of-concept is known, and no in-the-wild exploitation has been reported.

What to do: Audit OpenShift clusters for deployments of the Portworx Operator and consult the Pure Storage PSIRT advisory (CVE-2026-15140) for the fixed Operator version, since no version numbers are provided in this data. As an interim measure, restrict low-privileged, namespace-scoped users from interacting with the operator during initial provisioning of a Portworx storage cluster, and perform provisioning with trusted administrator credentials. After upgrading, verify that no unintended cluster-scoped permissions or role bindings were left behind from prior provisioning runs.

Affected
Pure Storage Portworx Operator (when deployed on Red Hat OpenShift)
Estimated exposure
moderatethousands of OpenShift clusters running the Portworx Operator (estimated; with only a subset exploitable during the initial-provisioning window) — Portworx is an enterprise-only Kubernetes storage product with no public active-install counts, and the flaw applies only to OpenShift deployments and only during initial provisioning with a low-privileged user, so the plausibly affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific conditions during the initial provisioning of a Portworx storage cluster, a user holding only limited, namespace-scoped permissions could cause the operator to grant broader access than intended, potentially resulting in elevated privileges within the Kubernetes cluster.

Weakness
CWE-266
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.