Injection Vulnerability in Data Science Pipelines Operator by Red Hat
CVE-2026-18617
8.8HIGH
What is CVE-2026-18617?
A vulnerability exists in the Data Science Pipelines Operator that allows namespace editors to exploit the spec.database.customExtraParams field, enabling them to inject harmful parameters into the MySQL Data Source Name (DSN) string. This manipulation can facilitate LOCAL INFILE functionality, granting attackers the ability to exfiltrate sensitive files, including service account tokens, from the operator pod. Such actions could lead to privilege escalation, potentially allowing the attacker to attain cluster-admin privileges.