Similar to HCSEC-2025-13 / CVE-2025-5999, a privileged operator could use the identity group subsystem to add a root policy to a group identity group, escalating their or another user's permissions in the system. Specifically this is an issue when:
identity/groups endpoints.Otherwise, an operator with policy access could create or modify an existing policy to grant root-equivalent permissions through the sudo capability.
Patched in version 2.4.4.
Users should audit the use of identity subsystem and deny operators access if it is not in use.
{
"github_reviewed_at": "2025-11-24T21:51:18Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-269"
],
"nvd_published_at": null,
"severity": "HIGH"
}