8.8
CVE-2026-18951
- EPSS 0.57%
- Veröffentlicht 10.08.2026 20:45:10
- Zuletzt bearbeitet 14.08.2026 19:07:46
- CVE-Watchlists
- Unerledigt
Odh-training-operator-rhel9: [trainer v2 security] trn-02: rhoai overlay aggregates trainjobs crud into standard edit clusterrole
A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit ClusterRole` permissions in a namespace to create, modify, and delete `TrainJobs`. When combined with a separate vulnerability (TRN-01) that permits arbitrary pod configurations, a remote attacker with namespace editor privileges could exploit this to escalate privileges, potentially leading to arbitrary code execution.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt
Red Hat OpenShift AI 3.3
Default Statusaffected
Version
1785188461
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat OpenShift AI 3.4
Default Statusaffected
Version
1784814352
Version <
*
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.57% | 0.444 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
https://access.redhat.com/security/cve/CVE-2026-18951
https://bugzilla.redhat.com/show_bug.cgi?id=2511187
https://access.redhat.com/errata/RHSA-2026:53263
https://access.redhat.com/errata/RHSA-2026:53262