Injection Vulnerability in Data Science Pipelines Operator by Red Hat
CVE-2026-18617

8.8HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
10 August 2026

What is CVE-2026-18617?

A vulnerability exists in the Data Science Pipelines Operator that allows namespace editors to exploit the spec.database.customExtraParams field, enabling them to inject harmful parameters into the MySQL Data Source Name (DSN) string. This manipulation can facilitate LOCAL INFILE functionality, granting attackers the ability to exfiltrate sensitive files, including service account tokens, from the operator pod. Such actions could lead to privilege escalation, potentially allowing the attacker to attain cluster-admin privileges.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.