Who Can Become Root? An SRE Guide to Access Drift and Privilege Escalation

No ratings

Presented at BSides Bristol 2026 by

Privilege escalation is not always a dramatic exploit, and in production systems it is often less about one clever trick than about a chain of ordinary operational decisions that were each made for a sensible reason, at a stressful moment, and without anyone stepping back later to ask what those decisions allowed when combined. This blue-team SRE talk asks a simple but uncomfortable question: who can become root? We will look at how temporary access, old service accounts, broad deploy permissions, and emergency exceptions can accumulate into hidden access paths that make people, processes, pipelines, or services more powerful than intended. Through a local, isolated demo, we will follow one flawed access path from a boring starting point to an uncomfortable ending, then reverse the story from the defender’s side to ask what evidence, containment, and guardrails would have exposed it earlier. Attendees will leave with a practical access-path review worksheet they can use to move beyond asking "who has admin?" and start asking the more useful question: "who can become admin?"