Pinniped Supervisor Privilege Escalation Vulnerability via Active Directory LDAP Injection

Vulnerability

A privilege escalation vulnerability has been identified in Pinniped Supervisor versions 0.11.0 through 0.46.0, inclusive. This issue arises when the Pinniped Supervisor is configured with an Active Directory Identity Provider and the group name attribute is left empty. Under these conditions, an attacker with knowledge of an Active Directory user's password and the ability to edit group distinguished names could manipulate group entries to gain elevated permissions in Kubernetes clusters.

Impact

Exploitation of this vulnerability could allow an authenticated user to gain elevated permissions in Kubernetes clusters, potentially leading to unauthorized access or modifications within the cluster.

Remediation

Users should upgrade to Pinniped Supervisor version 0.47.0 or later. For those using an Active Directory Identity Provider, it is also recommended to configure the group name attribute to a non-empty value. Additionally, preventing users from editing Active Directory LDAP group entries can mitigate this vulnerability.

Added: Jul 9, 2026, 8:26 AM
Updated: Jul 9, 2026, 8:26 AM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
4.9
remediation
8.3
relevance
9.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.