VDB

CVE-2026-18611

CVE-2026-18611 PUBLISHED CVSS 7.5 HIGH

Reported by redhat · Published August 10, 2026

A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords and MinIO access/secret keys, if they can access the MinIO Route or MariaDB Service. The flaw occurs because the operator uses a cryptographically weak pseudo-random number generator (PRNG) to generate these credentials, making them predictable. Successful exploitation could lead to unauthorized access to all pipeline artifacts and metadata, resulting in significant information disclosure.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Red HatRed Hat OpenShift AI 2.251785189332
Red HatRed Hat OpenShift AI 2.251788182334
Red HatRed Hat OpenShift AI 3.31785187936
Red HatRed Hat OpenShift AI 3.41784833428
Red HatRed Hat OpenShift AI 3.41787002057
Red HatRed Hat OpenShift AI 3.51786552271
Red HatRed Hat OpenShift AI 3.51786552250
Red HatRed Hat OpenShift AI 3.51786552271
Red HatRed Hat OpenShift AI 2.251788182334, 1785189332, 1788182334
Red HatRed Hat OpenShift AI (RHOAI)
Red HatRed Hat OpenShift AI 3.41787002057, 1784833428, 1787002057
Red HatRed Hat OpenShift AI 3.31785187936, 1785187936, 1785187936
Red HatRed Hat OpenShift AI 3.51786552250

Timeline

  • Aug 10, 2026 CVE Published
  • Aug 11, 2026 Coalition ESS Score
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 EPSS Score
  • Aug 28, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score
  • Sep 6, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›