Injection Vulnerability in Data Science Pipelines Operator by Red Hat
CVE-2026-18617
8.8HIGH
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 10 August 2026
What is CVE-2026-18617?
A vulnerability exists in the Data Science Pipelines Operator that allows namespace editors to exploit the spec.database.customExtraParams field, enabling them to inject harmful parameters into the MySQL Data Source Name (DSN) string. This manipulation can facilitate LOCAL INFILE functionality, granting attackers the ability to exfiltrate sensitive files, including service account tokens, from the operator pod. Such actions could lead to privilege escalation, potentially allowing the attacker to attain cluster-admin privileges.
Affected Version(s)
Red Hat OpenShift AI 2.25 1785189332
Red Hat OpenShift AI 3.3 1785187936
Red Hat OpenShift AI 3.4 1784833428