A large-scale study of more than 65,000 Kubernetes clusters found that built-in principals like system:anonymous and system:authenticated are still sometimes granted risky RBAC permissions. The findings highlight excessive and redundant bindings across AKS, EKS, and GKE, showing that many clusters could improve security by tightening authorization settings. #Kubernetes #AKS #EKS #GKE #RBAC
Keypoints
- Researchers analyzed RBAC configurations in over 65,000 Kubernetes clusters from nearly 10,000 organizations.
- The study focused on built-in principals such as system:anonymous, system:unauthenticated, and system:authenticated.
- More than 320,000 bindings to these principals were found, but many were removed as default Kubernetes bindings or obsolete podsecuritypolicy-related entries.
- After filtering, about 44,000 bindings remained for analysis, including over 3,500 bindings that granted dangerous permissions.
- AKS disables anonymous access by default, while EKS and GKE limit what anonymous users can reach; GKE also allows system:authenticated access by default to valid Google accounts.
- Some risky bindings were namespace-scoped, meaning a namespace-level admin could expose broader cluster resources through misconfiguration.
- The report concludes that many clusters would benefit from tighter RBAC rules, better maintenance, and removal of redundant permissions.
MITRE Techniques
- [T1098 ] Account Manipulation – RBAC bindings were used to assign permissions to built-in principals, expanding what users or groups can access (‘bindings that can grant some of the built-in principals wide-ranging access to cluster resources’).
- [T1068 ] Exploitation for Privilege Escalation – Dangerous RBAC permissions could let an attacker expand access within the cluster (‘allowing attackers to establish and expand their access to critical resources’).
- [T1525 ] Implant Internal Image – Not mentioned.
- [T1078 ] Valid Accounts – The article describes use of system:authenticated, which includes users with valid credentials and can be granted cluster permissions (‘system:authenticated… includes every user with valid credentials for the cluster’).
- [T1134 ] Access Token Manipulation – Not mentioned.
- [T1611 ] Escape to Host – Not mentioned.
Indicators of Compromise
- [Kubernetes API paths ] Publicly reachable endpoints granted to anonymous users – /healthz
- [Kubernetes built-in principals ] Subjects referenced in RBAC bindings – system:anonymous, system:unauthenticated
- [Kubernetes built-in group ] Authenticated-user group used in bindings – system:authenticated
- [Kubernetes distributions ] Affected environments discussed in the analysis – Amazon EKS, Google GKE, Microsoft AKS
- [Version / configuration flags ] Access-control settings and release references – –anonymous-auth=false, v1.34, v1.32, v1.35