Unit 42 Shows Node Root Can Steal SPIRE Identities

Unit 42 says root on a Kubernetes node can be turned into identity theft in SPIFFE/SPIRE deployments. In its research, the team showed that a node admin can spoof the cgroup data SPIRE uses for workload attestation and make the agent hand over a co-located workload's SPIFFE Verifiable Identity Document (SVID). That means the trust boundary is the node, not just the container. If an attacker gets root on one host, they may be able to impersonate other workloads running beside it and harvest the short-lived identities those services use to talk to each other. For Kubernetes operators and SPIFFE/SPIRE users, the lasting issue is blast radius: a host compromise can carry authenticated access into adjacent services, not stop at the machine itself. Unit 42 says it has not seen this used in the wild, but the proof-of-concept shows the assumption behind node-backed workload identity is already exploitable in the lab.

Part of the PlainSec briefing for 2026-09-10

Editions

Sources