The Kubernetes Dashboard acts with a service account. Older deployments shipped it bound to a very privileged account and allowed skipping login, so anyone who reached the UI inherited that power: reading secrets and creating workloads across the cluster through a browser.
# Find an exposed dashboard
curl -sk https://<host>/ | grep -i dashboard
# Legacy deployments expose a privileged service account; its token is in a secret
kubectl -n kubernetes-dashboard get secret -o name | grep dashboard
Exploitation notes#
- The impact is whatever the dashboard's service account holds; the classic misconfiguration is
cluster-adminplus skip-login. - Even with login required, the dashboard's own token (recoverable from its secret via another foothold) grants that account's rights.
- Creating a pod through the dashboard that mounts the host or runs privileged turns UI access into Pod escape to node.