7.6

CVE-2026-18621

Data-sciences-pipeline: dsp: v1 argo template path accepts arbitrary workflow spec, bypassing all v2 security hardening

A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code execution and full control over the underlying node.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
Produkt Red Hat OpenShift AI 2.25
Default Statusaffected
Version 1785189934
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat OpenShift AI 3.3
Default Statusaffected
Version 1785187920
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat OpenShift AI 3.4
Default Statusaffected
Version 1784924951
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat AI Inference Server
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat AI Inference Server
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat AI Inference Server
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat AI Inference Server
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat AI Inference Server
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat AI Inference Server
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat AI Inference Server
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat AI Inference Server
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat AI Inference Server
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat AI Inference Server
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat AI Inference Server
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat AI Inference Server
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat AI Inference Server
Default Statusunaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.279
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 7.6 2.8 4.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
CWE-266 Incorrect Privilege Assignment

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

https://access.redhat.com/security/cve/CVE-2026-18621
https://bugzilla.redhat.com/show_bug.cgi?id=2510327
https://access.redhat.com/errata/RHSA-2026:53263
https://access.redhat.com/errata/RHSA-2026:53261
https://access.redhat.com/errata/RHSA-2026:53262