Privilege Escalation Flaw in Red Hat OpenShift AI Service
CVE-2025-10725

9.9CRITICAL

Key Information:

Badges

📈 Score: 138📰 News Worthy

What is CVE-2025-10725?

CVE-2025-10725 is a privilege escalation vulnerability identified in the Red Hat OpenShift AI Service, which is designed to manage and deploy artificial intelligence applications on the OpenShift platform. This flaw allows a low-privileged attacker, who has access to an authenticated account—such as a data scientist utilizing a standard Jupyter notebook—to escalate their privileges to that of a full cluster administrator. The technical details reveal that this escalation could lead to the complete compromise of the cluster's confidentiality, integrity, and availability. If exploited, the attacker can gain unfettered access to sensitive data, disrupt operations, and take control of the underlying infrastructure, ultimately leading to a comprehensive breach of the platform and all applications hosted within it.

Potential impact of CVE-2025-10725

  1. Data Breach: The vulnerability allows attackers to access sensitive information within the cluster, leading to potential data theft or unauthorized disclosure of critical data assets.

  2. Service Disruption: By escalating privileges, an attacker can disrupt the services running on the OpenShift platform, potentially causing significant downtime and impacting business operations.

  3. Infrastructure Control: Full administrative access enables the attacker to manipulate the entire infrastructure, leading to uncontrolled changes, potential malware deployment, or further exploits within the network.

Affected Version(s)

Red Hat OpenShift AI 2.16 sha256:cebc8815e03b772343b15d0a7dce8fad6fcc71dd437d871db5a3691472350803

Red Hat OpenShift AI 2.19 sha256:43a8904396e55074ffb1afcfcd8fe6db0edcbc918a8ff8301b6b0920aea7eabf

Red Hat OpenShift AI 2.21 sha256:66e2c3916ae1cdb08edab90f0868965b26991ce43fb120db7f2d05311d90c9c8

News Articles

Red Hat OpenShift AI Flaw Exposes Hybrid Cloud Infrastructure to Full Takeover

Severe flaw CVE-2025-10725 in Red Hat OpenShift AI risks full cluster compromise.

4 weeks ago

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-10725 : Privilege Escalation Flaw in Red Hat OpenShift AI Service