A user authenticating to Kubernetes clusters via the Pinniped Supervisor
Low3.8CVE-2026-59269 · Published Jul 9, 2026
A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in the clusters, only if all the following conditions were true: the Pinniped Supervisor server is running with an ActiveDirectoryIdentityProvider resource configured; the ActiveDirectoryIdentityProvider.spec.groupSearch.attributes.groupName is empty; the attacker gains the ability to edit some part of the distinguished name (DN) of group entries in the Active Directory (AD) server's database for groups to which they belong; the configured group search parameters cause the edited group to be included in the group search results for the user; and the attacker knows the password for an AD user who belongs to the edited AD group. Affected versions: Pinniped (go.pinniped.dev) v0.11.0 through v0.46.0 inclusive; fixed in v0.47.0.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Pinniped Product | >= 0.11.0, <= 0.46.0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
More VMware advisories
All VMware| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 9 | VMware bosh-cli: argument injection | High7.7 | 7.10.4 |
| Jul 9 | VMware bosh-windows-stemcell-builder: insecure permissions | High8.5 | 2019.98 |
| Jul 9 | VMware bosh-windows-stemcell-builder: remote attacker could brute-force the... | High7.7 | 2019.98 |
| Jul 9 | A network attacker positioned between UAA and its LDAP directory can... | Critical9.3 | UAA 78.13.0+1 more |
| Jul 9 | VMware BOSH CLI tool: information disclosure | High8.5 | 7.10.4 |
| Jul 9 | VMware bosh-cli: remote code execution | High8.9 | 7.10.4 |