Identity · 20h ago
Datadog Security Labs analyzed more than 65,000 Kubernetes clusters and found that dangerous RBAC bindings to built-in principals are common. The study looked at system:anonymous, system:unauthenticated, and system:authenticated across clusters from nearly 10,000 organizations.
The issue is simple: Kubernetes can hand permissions to those built-in identities, so any request that matches them inherits the role attached to the binding. That means a cluster can still expose broad API access through old or redundant grants even when a distribution’s default hardening limits anonymous access.
The practical lesson is that distribution-specific defaults do not erase existing permissions already attached to the API server’s identity model. For teams running EKS, GKE, AKS, or upstream Kubernetes, the exposure can live in legacy RBAC state long after the platform’s default posture changed.
1 source covering this story
We analyzed RBAC bindings across over 65,000 Kubernetes clusters to find dangerous permissions granted to system:anonymous, system:unauthenticated, and system:authenticated.
Part of the PlainSec briefing for 2026-10-05