VDB

CVE-2026-18620

CVE-2026-18620 PUBLISHED CVSS 7.1 HIGH

Reported by redhat · Published August 10, 2026

A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged ServiceAccount (SA) during a CreateRun request, an attacker can bypass authorization checks. This allows the tenant to run their containers with elevated privileges, potentially leading to the disclosure of sensitive information (secrets) and the ability to execute commands within other users' pods.

Risk Scores

CVSS 3.1
7.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Affected Products

VendorProductVersions
Red HatRed Hat OpenShift AI 2.251785189934
Red HatRed Hat OpenShift AI 2.251788256711
Red HatRed Hat OpenShift AI 3.31785187920
Red HatRed Hat OpenShift AI 3.41784924951
Red HatRed Hat OpenShift AI 3.41787173417
Red HatRed Hat OpenShift AI 3.51786552271
Red HatRed Hat OpenShift AI 3.51786552250
Red HatRed Hat OpenShift AI 3.41787173417, 1787173417, 1784924951
Red HatRed Hat OpenShift AI (RHOAI)
Red HatRed Hat OpenShift AI 3.31785187920, 1785187920, 1785187920
Red HatRed Hat OpenShift AI 3.51786552271
Red HatRed Hat OpenShift AI 2.251788256711, 1785189934, 1785189934
Red HatRed Hat OpenShift AI 3.51786552250

Timeline

  • Aug 10, 2026 CVE Published
  • Aug 11, 2026 Coalition ESS Score
  • Aug 24, 2026 EPSS Score
  • Aug 27, 2026 EPSS Score
  • Aug 28, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 4, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
  • Sep 21, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›