Improper Authorization Vulnerability in Data Science Pipelines by Red Hat
CVE-2026-18620

7.1HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
10 August 2026

What is CVE-2026-18620?

A flaw exists in Data Science Pipelines, allowing a restricted user to exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By submitting a more privileged ServiceAccount during the CreateRun request, an attacker can bypass necessary authorization checks. This can enable the attacker to run containers with escalated privileges, which could lead to the unauthorized disclosure of sensitive information and the ability to execute commands across different users' pods.

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.