EPScan: Automated Detection of Excessive RBAC Permissions in Kubernetes Applications
Yue Gu, Xin Tan, Yuan Zhang, Siyan Gao, Min Yang
Abstract
As the dominant container orchestration system, Kubernetes has a large ecosystem of third-party applications. The third-party Kubernetes applications access various cluster resources to extend the cluster functionality and Kubernetes adopts the RBAC mechanism to manage the resource access permissions. Recently, researchers revealed that third-party applications are granted excessive permissions and proposed an excessive permission attack. The attacker can exploit some critical excessive permissions to escape from the worker node and take over the whole Kubernetes cluster. However, this attack assumes that the attacker has compromised a worker node via container escape, which is difficult to realize in real scenarios.
Therefore, we propose a new excessive permission attack with simpler attack conditions in this paper. We reveal that an attacker who has compromised one pod (less difficult than compromising a worker node) can exploit some other excessive privileges to take over worker nodes or break the availability and data confidentiality of other pods. Although excessive permissions of third-party applications pose a great threat to the security of Kubernetes clusters, there is no effective approach for detecting them.
In this paper, we propose a novel approach, namely EPScan, which automatically detects exploitable excessive permissions in third-party applications. To achieve this, EPScan employs a novel pod-oriented program analysis, which utilizes several new techniques to accurately identify the resource access behavior of the programs running in each pod. EPScan then compares the permissions required for these behaviors with those requested by the pod in its configuration file and finally reports the exploitable permissions that can be abused to launch an excessive permissions attack. We applied EPScan on 108 third-party applications from the CNCF projects and discovered previously unknown exploitable excessive permissions in 106 pods across 50 applications with a precision of 94.6% and 9 CVE identifiers assigned.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 95d6ebda-e8d6-491a-9033-a8f531cd42dbCited by top-tier papers3
- Breaking the Bulkhead: Demystifying Cross-Namespace Reference Vulnerabilities in Kubernetes OperatorsAndong Chen, Ziyi Guo, Zhaoxuan Jin, Zhenyuan Li et al.NDSS 2026 · 2 citations
- ALPS: Automated Least-Privilege Enforcement for Securing Serverless FunctionsChanghee Shin, Bom Kim, Seungsoo LeeINFOCOM 2026 · 1 citation
- PatchWeaver: Risk-Bounded Autonomous Vulnerability Remediation Under Change-Management PoliciesRui Li, Shuang CaoUSENIX Security 2026
Builds on5
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- Harvesting Inconsistent Security Configurations in Custom Android ROMs via Differential AnalysisYousra Aafer, Xiao Zhang, Wenliang DuUSENIX Security 2016 · 43 citations
- Android Custom Permissions Demystified: From Privilege Escalation to Design ShortcomingsRui Li, Wenrui Diao, Zhou Li, Jianqi Du et al.S&P 2021 · 32 citations
- Take Over the Whole Cluster: Attacking Kubernetes via Excessive Permissions of Third-party ApplicationsNanzi Yang, Wenbo Shen, Jinku Li, Xunqi Liu et al.CCS 2023 · 15 citations
- Credit Karma: Understanding Security Implications of Exposed Cloud Services through Automated Capability InferenceXueqiang Wang, Yuqiong Sun, Susanta Nanda, XiaoFeng WangUSENIX Security 2023
Related papers
- Dangers Behind Access Control: Understanding and Exploiting Implicit Permissions in KubernetesNanzi Yang, Xingyu Liu, Wenbo Shen, Jinku Li et al.CCS 2025
- Cross Container Attacks: The Bewildered eBPF on CloudsYi He, Roland Guo, Yunlong Xing, Xijia Che et al.USENIX Security 2023
- An Empirical Study and Benchmark of Kubernetes Misconfiguration ScannersHaeun Eom, Bohyun Suk, Sungjae HwangISSTA 2026
- Understanding Resource Injection Vulnerabilities in Kubernetes EcosystemsDefang Bo, Jie Lu, Feng Li, Jingting Chen et al.ASE 2025
- Containing Malicious Package Updates in npm with a Lightweight Permission SystemGabriel Ferreira, Limin Jia, Joshua Sunshine, Christian KästnerICSE 2021 · 3 citations
