{"id":"CVE-2026-79767","summary":"Gardener: Authorization Bypass via Group Subject Injection","details":"Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142.6, 1.143.3, 1.144.2, and 1.145.0, the customverbauthorizer admission plugin's mustCheckProjectMembers manage-members check compares changes to User subjects but does not account for Group or ServiceAccount subjects in Project.spec.members. A project administrator who lacks manage-members permission can add arbitrary Group or ServiceAccount subjects, including the system:authenticated Group, and thereby grant broad project access. The resulting access can include Shoots, Secrets, and cloud provider credentials. This issue is fixed in versions 1.142.6, 1.143.3, 1.144.2, and 1.145.0.","aliases":["GHSA-gfjv-gqf2-c888"],"modified":"2026-09-25T03:31:10.622740141Z","published":"2026-09-22T19:58:00.090Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79767.json"},"references":[{"type":"WEB","url":"https://github.com/gardener/gardener/releases/tag/v1.144.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79767.json"},{"type":"ADVISORY","url":"https://github.com/gardener/gardener/security/advisories/GHSA-gfjv-gqf2-c888"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79767"},{"type":"FIX","url":"https://github.com/gardener/gardener/commit/63751db97dca6cc5ee5f966d4963415de6ae5545"},{"type":"FIX","url":"https://github.com/gardener/gardener/pull/15080"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gardener/gardener","events":[{"introduced":"0"},{"introduced":"94a9a9b336f8fb405e43a5059e2faf5bc99751c1"},{"introduced":"294cdc82ff08930c750343e30b19dfd3c049d536"},{"fixed":"a08f4bdb8a4493c08e6f9daa68f5ae63e86919f7"},{"fixed":"76510c1dd92bbff48e72d05ee291a0f0fd2f986a"},{"fixed":"c4521180a208e4c2d798fac6071b6a157c3ed13f"},{"fixed":"63751db97dca6cc5ee5f966d4963415de6ae5545"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.142.6"},{"introduced":"1.143.0"},{"fixed":"1.143.3"},{"introduced":"1.144.0"},{"fixed":"1.144.2"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v1.142.5","pkg/apis/v1.142.5","v1.143.2","pkg/apis/v1.143.2","v1.144.1","pkg/apis/v1.144.1","v1.144.0","pkg/apis/v1.144.0","v1.142.4","pkg/apis/v1.142.4","v1.143.1","pkg/apis/v1.143.1","v1.142.3","pkg/apis/v1.142.3","v1.143.0","pkg/apis/v1.143.0","v1.142.2","pkg/apis/v1.142.2","v1.142.1","pkg/apis/v1.142.1","v1.142.0","pkg/apis/v1.142.0","v1.73.0","v1.72.0","v1.71.0","v1.70.0","v1.69.0","v1.68.0","v1.67.0","v1.66.0","v1.65.0","v1.64.0","v1.63.0","v1.62.0","v1.61.0","v1.60.0","v1.59.0","v1.58.0","v1.57.0","v1.56.0","v1.55.0","v1.54.0","v1.53.0","v1.52.0","v1.51.0","v1.50.0","v1.49.0","v1.48.0","v1.47.0","v1.46.0","v1.45.0","v1.44.0","v1.43.0","v1.42.0","v1.41.0","v1.40.0","v1.39.0","v1.38.0","v1.37.0","v1.36.0","v1.35.0","v1.34.0","v1.33.0","v1.32.0","v1.31.0","v1.30.0","v1.29.0","v1.28.0","v1.27.0","v1.26.0","v1.25.0","v1.24.0","v1.23.0","v1.22.0","v1.21.0","v1.20.0","v1.19.0","v1.17.0","v1.16.0","v1.15.0","v1.14.0","v1.13.0","v1.12.0","v1.11.0","v1.10.0","v1.9.0","v1.8.0","v1.7.0","v1.6.0","v1.5.0","v1.4.0","v1.3.0","v1.2.0","v1.1.0","v1.0.0","v0.35.0","v0.34.0","v0.33.0","v0.32.0","0.31.0","0.30.0","0.29.0","0.28.0","0.27.0","0.26.0","0.25.0","0.24.0","0.23.0","0.22.0","0.21.0","0.20.0","0.19.0","0.18.0","0.17.0","0.16.0","0.15.0","0.14.0","0.13.0","0.12.0","0.11.0","0.10.0","0.9.0","0.8.0","0.7.0","0.6.0","0.5.0","0.4.0","0.3.0","0.2.0","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79767.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N"}]}