# Kubernetes permissions can expose Google Cloud organizations through Config Connector

_Published Wednesday, September 23, 2026 at 10:53 AM EDT · Security, Infrastructure · Latest · Tier 2 — Notable_

![Kubernetes permissions can expose Google Cloud organizations through Config Connector — Primary](https://www.bleepstatic.com/content/posts/2026/09/22/screwdriver-stealing-card.jpg)

A configuration of Google Kubernetes Config Connector can let a user with limited cluster access grant themselves broad Google Cloud permissions, security researcher Justin O'Leary found. The user needs permission to create an IAM policy resource in a namespace watched by the connector; the connector then submits the requested change through its own Google service account.

If that service account has organization-level authority, Google Cloud accepts a request the Kubernetes user could not make directly. The exposure depends on both broad connector permissions and access to submit the relevant resource. Google says the connector is working as designed and recommends limiting its authority.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/how-one-kubernetes-yaml-can-hand-over-a-gcp-organization/)

---
Canonical: https://techandbusiness.org/newswire/L2UCKi1vnNdVXUmwaazAod
Published: 2026-09-23T14:53:11.159Z
Story chronology: 2026-09-23T14:01:11.000Z
Retrieved: 2026-09-23T16:47:22.949Z
Publisher: Tech & Business (techandbusiness.org)
