Authorization Token Theft in Kubeflow Community Distribution
CVE-2026-47237
8HIGH
What is CVE-2026-47237?
The Kubeflow Community Distribution is susceptible to an authorization token theft vulnerability. This affects users who engage with the Kubeflow UI or APIs – including the Dashboard, Pipelines API, and Notebooks. An attacker can exploit this vulnerability to gain unauthorized access to a user’s account and their processed data, provided they already possess a valid user role such as 'kubeflow-edit' or 'Contributor' within a Kubeflow namespace. This scenario is made possible when the 'Automatic Profile Creation' feature is enabled. It is crucial to update to version 26.03-rc.1 or later to mitigate this security risk.
Affected Version(s)
community-distribution < 26.03-rc.1
