VDB
CVE-2026-18621
CVE-2026-18621
PUBLISHED
CVSS 7.6 HIGH
Reported by redhat · Published August 10, 2026
A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code execution and full control over the underlying node.
Risk Scores
CVSS 3.1
7.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat OpenShift AI 2.25 | 1785189934 |
| Red Hat | Red Hat OpenShift AI 2.25 | 1788256711 |
| Red Hat | Red Hat OpenShift AI 3.3 | 1785187920 |
| Red Hat | Red Hat OpenShift AI 3.4 | 1784924951 |
| Red Hat | Red Hat OpenShift AI 3.4 | 1787173417 |
| Red Hat | Red Hat AI Inference Server | |
| Red Hat | Red Hat AI Inference Server | |
| Red Hat | Red Hat AI Inference Server | |
| Red Hat | Red Hat AI Inference Server | |
| Red Hat | Red Hat AI Inference Server | |
| Red Hat | Red Hat AI Inference Server | |
| Red Hat | Red Hat AI Inference Server | |
| Red Hat | Red Hat AI Inference Server | |
| Red Hat | Red Hat AI Inference Server | |
| Red Hat | Red Hat AI Inference Server | |
| Red Hat | Red Hat AI Inference Server | |
| Red Hat | Red Hat AI Inference Server | |
| Red Hat | Red Hat AI Inference Server | |
| Red Hat | Red Hat AI Inference Server | |
| Red Hat | Red Hat AI Inference Server |
…and 15 more
Timeline
- Aug 10, 2026 CVE Published
- Aug 11, 2026 Coalition ESS Score
- Aug 19, 2026 CVE Updated
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 4, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 9, 2026 Distribution Patch
- Sep 9, 2026 Distribution Patch
- Sep 9, 2026 Distribution Patch
References
- RHSA-2026:53261 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:53262 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:53263 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:60520 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:65126 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2510327 issue-trackingx_refsource_REDHAT