A pod service account is an identity

Every pod runs as an identity, and by default it may be one with more access than the workload needs.

That token is mounted into the container and is available to anything running there, including anything an attacker gets executing. Turning off automatic mounting where it is not needed, and scoping it tightly where it is, removes a well-used escalation path.

More on Kubernetes