Excessive Privileges in Red Hat OpenShift AI Service Accounts
CVE-2026-15218

7.9HIGH

What is CVE-2026-15218?

A vulnerability exists in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI, where these accounts possess cluster-wide permissions that are greater than necessary. If an attacker compromises these ServiceAccounts—through a remote code execution flaw or by deploying a malicious pod within the same namespace—they can exploit these excessive permissions. This exploitation could enable the attacker to gain full cluster administrator privileges by creating new ClusterRoleBindings or accessing sensitive information through the retrieval of all secrets within the cluster.

Affected Version(s)

Red Hat OpenShift AI 3.4 1787153683

References

CVSS V3.1

Score:
7.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.