Google Denies Bug Bounty for Critical Kubernetes Flaw Still Unfixed

Google Denies Bug Bounty for Critical Kubernetes Flaw Still Unfixed

First seen 19 Jun 2026, 15:50 UTC TheregisterCybernews 85% similarity 66.0

Article Content

Browse articles
ThreatCluster

Researcher Justin O'Leary discovered a significant vulnerability in Google Cloud's Kubernetes operator, allowing users to bypass Identity and Access Management (IAM) controls. Initially rated as high priority, Google later claimed the issue was 'working as intended' and refused to pay a bug bounty. The flaw, named ConfigConfusion, enables any Config Connector service account with org-level permissions to gain root access to an entire GCP Organization. Despite being flagged as P1/S1 severity, the vulnerability remains unfixed as of June 2026. O'Leary's findings were reported to Google on March 8, 2026, and the communication from Google changed abruptly on April 7, 2026. This situation raises concerns about Google's transparency and the effectiveness of its bug bounty program.

Key Points: • A critical vulnerability in Google Cloud's Kubernetes operator allows unauthorized access. • Google initially acknowledged the flaw but later denied a bug bounty, claiming it was intended behavior. • The vulnerability remains unfixed and is marked with the highest severity rating.

ThreatCluster AI How this analysis works

Timeline

2026-03-08
O'Leary reports vulnerability to Google
Justin O'Leary submits a report on a flaw in Google Cloud's Kubernetes operator, named ConfigConfusion.
The Register
2026-03-27
Google acknowledges the flaw
A Google security engineer accepts O'Leary's report and rates it as high priority and severity.
The Register
2026-04-07
Google reverses decision on vulnerability
A Google bot informs O'Leary that the issue does not qualify for a reward and is working as intended.
The Register
2026-06-19
Vulnerability remains unfixed
As of today, the ConfigConfusion vulnerability is still active and unaddressed by Google.
Cybernews

Community

Browse all →