CVE-2026-15140
moderatePrivilege Escalation in Portworx Operator on Red Hat OpenShift
CVE-2026-15140 is an incorrect privilege assignment flaw (CWE-266) in the Portworx Operator when it is deployed on Red Hat OpenShift. It can be triggered only under specific conditions during the initial provisioning of a Portworx storage cluster, when a user holding only limited, namespace-scoped permissions causes the operator to grant broader access than intended. An attacker who is able to trigger the flaw gains elevated privileges within the Kubernetes/OpenShift cluster, beyond the namespace-scoped access they legitimately hold. Only organizations running the Portworx Operator on OpenShift are affected, and only during that narrow provisioning window. The flaw is not in CISA's Known Exploited Vulnerabilities catalog, no public proof-of-concept is known, and no in-the-wild exploitation has been reported.
What to do: Audit OpenShift clusters for deployments of the Portworx Operator and consult the Pure Storage PSIRT advisory (CVE-2026-15140) for the fixed Operator version, since no version numbers are provided in this data. As an interim measure, restrict low-privileged, namespace-scoped users from interacting with the operator during initial provisioning of a Portworx storage cluster, and perform provisioning with trusted administrator credentials. After upgrading, verify that no unintended cluster-scoped permissions or role bindings were left behind from prior provisioning runs.
| Pure Storage Portworx Operator (when deployed on Red Hat OpenShift) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific conditions during the initial provisioning of a Portworx storage cluster, a user holding only limited, namespace-scoped permissions could cause the operator to grant broader access than intended, potentially resulting in elevated privileges within the Kubernetes cluster.
- Weakness
- CWE-266
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.