High severityNVD Advisory· Published Sep 9, 2026
CVE-2026-15140
CVE-2026-15140
Description
A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific conditions during the initial provisioning of a Portworx storage cluster, a user holding only limited, namespace-scoped permissions could cause the operator to grant broader access than intended, potentially resulting in elevated privileges within the Kubernetes cluster.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.