[kubernetes] CVE-2026-2270: StatefulSet and ControllerRevision write permissions allow cross-namespace pod creation
A Kubernetes StatefulSet flaw lets namespace-scoped writers create a pod in another namespace.
CVE-2026-2270 is a confused-deputy flaw in the Kubernetes StatefulSet controller. A user with namespace-scoped write permissions on StatefulSet and ControllerRevision objects can cause creation of a pod in another namespace. The attacker has full control of the pod's metadata and specification, including the target namespace. The disclosure notes the cross-namespace pod is immediately deleted and does not report in-the-wild exploitation.
48