Identity & Access · Misconfiguration

Datadog Finds Kubernetes RBAC Defaults Still Linger

Datadog Security Labs analyzed more than 65,000 Kubernetes clusters and found that dangerous RBAC bindings to built-in principals are common. The study looked at system:anonymous, system:unauthenticated, and system:authenticated across clusters from nearly 10,000 organizations.

The issue is simple: Kubernetes can hand permissions to those built-in identities, so any request that matches them inherits the role attached to the binding. That means a cluster can still expose broad API access through old or redundant grants even when a distribution’s default hardening limits anonymous access.

The practical lesson is that distribution-specific defaults do not erase existing permissions already attached to the API server’s identity model. For teams running EKS, GKE, AKS, or upstream Kubernetes, the exposure can live in legacy RBAC state long after the platform’s default posture changed.

1 source · 21h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-10-05

Every edition of this story: Datadog Finds Kubernetes RBAC Defaults Still Linger