Improper Authorization Vulnerability in Data Science Pipelines by Red Hat
CVE-2026-18620

7.1HIGH

What is CVE-2026-18620?

A flaw exists in Data Science Pipelines, allowing a restricted user to exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By submitting a more privileged ServiceAccount during the CreateRun request, an attacker can bypass necessary authorization checks. This can enable the attacker to run containers with escalated privileges, which could lead to the unauthorized disclosure of sensitive information and the ability to execute commands across different users' pods.

Affected Version(s)

Red Hat OpenShift AI 2.25 1785189934

Red Hat OpenShift AI 3.3 1785187920

Red Hat OpenShift AI 3.4 1784924951

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.