VDB
CVE-2026-18617
CVE-2026-18617
PUBLISHED
CVSS 8.8 HIGH
Reported by redhat · Published August 10, 2026
A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Source Name (DSN) string. By manipulating these parameters, an attacker can enable LOCAL INFILE functionality and exfiltrate sensitive files, such as the service account token, from the operator pod. This can lead to privilege escalation, allowing a namespace editor to gain cluster-admin privileges.
Risk Scores
CVSS 3.1
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat OpenShift AI 2.25 | 1785189332 |
| Red Hat | Red Hat OpenShift AI 2.25 | 1788182334 |
| Red Hat | Red Hat OpenShift AI 3.3 | 1785187936 |
| Red Hat | Red Hat OpenShift AI 3.4 | 1784833428 |
| Red Hat | Red Hat OpenShift AI 3.4 | 1787002057 |
| Red Hat | Red Hat OpenShift AI 3.5 | 1786552271 |
| Red Hat | Red Hat OpenShift AI 3.5 | 1786552250 |
| Red Hat | Red Hat OpenShift AI 3.4 | 1784833428, 1787002057, 1784833428 |
| Red Hat | Red Hat OpenShift AI 2.25 | 1788182334, 1785189332, 1785189332 |
| Red Hat | Red Hat OpenShift AI 3.3 | 1785187936, 1785187936, 1785187936 |
| Red Hat | Red Hat OpenShift AI 3.5 | 1786552250 |
| Red Hat | Red Hat OpenShift AI 3.5 | 1786552271 |
| Red Hat | Red Hat OpenShift AI (RHOAI) |
Timeline
- Aug 10, 2026 CVE Published
- Aug 11, 2026 Coalition ESS Score
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 3, 2026 EPSS Score
- Sep 6, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
References
- RHSA-2026:53261 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:53262 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:53263 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:60367 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:60520 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:65126 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2510304 issue-trackingx_refsource_REDHAT