CVE-2026-15140

Summary

A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific conditions during the initial provisioning of a Portworx storage cluster, a user holding only limited, namespace-scoped permissions could cause the operator to grant broader access than intended, potentially resulting in elevated privileges within the Kubernetes cluster.

Affected Software

VendorProductVersion RangeStatus
EverpurePortworx Operator0 <= 26.3.1affected
EverpurePortworx Operator26.3.2 +unaffected

Weaknesses

  • CWE-266: CWE-266 Incorrect privilege assignment

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References