Cybernews Google Denies Bug Bounty for Critical Kubernetes Flaw Still Unfixed
Article Content
- •A critical vulnerability in Google Cloud's Kubernetes operator allows unauthorized access.
- •Google initially acknowledged the flaw but later denied a bug bounty, claiming it was intended behavior.
- •The vulnerability remains unfixed and is marked with the highest severity rating.
Researcher Justin O'Leary discovered a significant vulnerability in Google Cloud's Kubernetes operator, allowing users to bypass Identity and Access Management (IAM) controls. Initially rated as high priority, Google later claimed the issue was 'working as intended' and refused to pay a bug bounty. The flaw, named ConfigConfusion, enables any Config Connector service account with org-level permissions to gain root access to an entire GCP Organization. Despite being flagged as P1/S1 severity, the vulnerability remains unfixed as of June 2026. O'Leary's findings were reported to Google on March 8, 2026, and the communication from Google changed abruptly on April 7, 2026. This situation raises concerns about Google's transparency and the effectiveness of its bug bounty program.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Google in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…