Two Kubernetes CVEs disclosed: StatefulSet cross-namespace pod creation (CVE-2026-2270) and Windows subPath NTLM coercion (CVE-2026-76654)
Two Kubernetes vulnerabilities were disclosed via oss-security on 2026-09-23: a confused-deputy flaw allowing namespace-scoped writers to create pods in another namespace, and a Windows kubelet flaw that can be coerced into NTLM authentication via a volume…
Two separate Kubernetes vulnerabilities were disclosed on oss-security on 2026-09-23. CVE-2026-2270 is a confused-deputy flaw in the Kubernetes StatefulSet controller: a user with namespace-scoped write permissions on StatefulSet and ControllerRevision objects can cause a pod to be created in another namespace, with full attacker control over the pod's metadata and specification, including the target namespace. The disclosure notes the cross-namespace pod is immediately deleted. CVE-2026-76654 affects Kubernetes Windows nodes: if a pod volumeMount subPath is a symbolic link to an attacker-controlled UNC share, the kubelet resolves the link without rejecting the UNC target and attempts NTLM authentication to that share, allowing an attacker to capture a NetNTLMv2 authentication response. Neither disclosure reports exploitation in the wild.
- Both CVEs were disclosed via oss-security on 2026-09-23.
- CVE-2026-2270 requires namespace-scoped write permissions on StatefulSet and ControllerRevision objects.
- CVE-2026-2270 allows creation of a pod in another namespace, with attacker control of the pod's metadata and full specification including the target namespace.
- CVE-2026-2270: the cross-namespace pod is immediately deleted.
- CVE-2026-76654 affects Windows nodes, where the kubelet follows a volumeMount subPath symlink to a UNC path and does not reject attacker-controlled network share targets.
- CVE-2026-76654: the kubelet authenticates to the attacker's share using NTLM, enabling capture of a NetNTLMv2 response.
- Neither disclosure reports in-the-wild exploitation.
Coverage timelineoldest first · each row is one article
- · 3d ago[kubernetes] CVE-2026-2270: StatefulSet and ControllerRevision write permissions allow cross-namespace pod creation
oss-security· 48
A Kubernetes StatefulSet flaw lets namespace-scoped writers create a pod in another namespace.
- · 3d ago[kubernetes] CVE-2026-76654: Subpath symlinking on Windows nodes permits NTLM coercion
oss-security· 58
Kubernetes Windows nodes can be coerced into NTLM authentication via a subPath symlink to an attacker UNC share.
Vulnerabilities in this storyAll →
- published —
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-2270 | NVD description · AI analysis pending | — | — |