9.9

CVE-2026-14450

Maas-billing: maas api: privilege escalation via forged http headers due to missing authentication

A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are trusted verbatim. This lack of first-party authentication enables an attacker to gain unauthorized access and escalate privileges. The concrete consequences include the ability to mint Kubernetes ServiceAccount tokens in other tenants' namespaces, revoke API keys, and exfiltrate sensitive model access configuration.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
Produkt Red Hat OpenShift AI 3.4
Default Statusaffected
Version 1785850409
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat OpenShift AI (RHOAI)
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat OpenShift AI (RHOAI)
Default Statusunaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.373
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 9.9 3.1 6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-290 Authentication Bypass by Spoofing

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

https://access.redhat.com/security/cve/CVE-2026-14450
https://bugzilla.redhat.com/show_bug.cgi?id=2496373
https://access.redhat.com/errata/RHSA-2026:53262