I understand that if one node is compromised, it can then be used to generate malicious txs and the attacker can try to add them to a block it generates, but why would you say the other validators accept such block(s) or transactions in the first place?
It seems to me that a successful attack on a private blockchain requires the attacker gaining access to both a "pre-approved" node and having the hashrate majority needed to ensure its blocks are generated faster than the rest of the network combined.