Authentication Bypass Vulnerability in MaaS API by Red Hat
CVE-2026-14450

9.9CRITICAL

What is CVE-2026-14450?

A vulnerability exists in the MaaS API that enables any pod within the Kubernetes cluster to circumvent the Kuadrant AuthPolicy gateway by manipulating HTTP headers, specifically X-MaaS-Username and X-MaaS-Group. This flaw allows attackers to gain unauthorized access and escalate privileges, leading to severe consequences such as the ability to create Kubernetes ServiceAccount tokens in other tenants' namespaces, revoke API keys, and exfiltrate sensitive access configurations.

Affected Version(s)

Red Hat OpenShift AI 3.4 1785850409

Red Hat OpenShift AI 3.4 1787153683

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.